Sviluppo · Server MCP remoto
ShipSafe - Independent security verification
Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access.
Vai al sito web di ShipSafe - Independent security verification
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
co.ship-safe/scanner- Versione
- 0.6.4
- Stato
- Attivo
- Categoria
- sviluppo
- Trasporto
- Streamable HTTP e stdio (processo locale)
- Pacchetto
- npm
- Pubblicato
- 28 settembre 2026
- Aggiornato
- 28 settembre 2026
- Editore
- co.ship-safe
- Namespace
- Namespace verificato dal MCP Registry tramite il dominio ship-safe.co · come funziona
- Sito web
- ship-safe.co
- Fonte
- Voce nell’API del registro
Endpoint remoti
| Trasporto | URL | Header dichiarati |
|---|---|---|
| Streamable HTTP | https://ship-safe.co/api/mcp | Authorization (obbligatorio, segreto) |
Verifica live
Questa directory si è collegata a ogni endpoint remoto e ne ha richiesto l’elenco degli strumenti. La verifica si limita a collegarsi e a elencare gli strumenti; non li esegue, non effettua l’accesso e non testa la sicurezza.
- Raggiungibile
- Sì (HTTP 401)
- Handshake
- Non completato: accesso richiesto
- Accesso richiesto
- Sì - HTTP 401; viene richiesto un token Bearer
- Data della verifica
- 5 ottobre 2026
Pacchetti
| Registro | Pacchetto | Versione | Trasporto |
|---|---|---|---|
| npmruntime: npx | @ship-safe/mcp | 0.6.4 | stdio |
Come collegare ShipSafe - Independent security verification
ShipSafe - Independent security verification è un server MCP remoto: non c’è niente da installare. Il suo endpoint, servito tramite Streamable HTTP, è https://ship-safe.co/api/mcp. In un assistente che accetta server MCP remoti (spesso in un’impostazione chiamata connettori, integrazioni o strumenti) si aggiunge un nuovo server indicando questo URL; in un client configurato tramite file lo si aggiunge come server remoto (HTTP) con lo stesso URL.
La voce del registro dichiara un header HTTP per la connessione: Authorization (obbligatorio, segreto). Un header segreto contiene di solito una chiave API o un token rilasciato dal servizio; i client che accettano header personalizzati lo impostano insieme all’URL del server.
Può essere eseguito anche in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @ship-safe/mcp, versione 0.6.4. Comunica via MCP su stdio, quindi il client lo avvia come programma e dialoga con esso tramite standard input e standard output. Richiede Node.js; i client in genere lo avviano con npx - il comando abituale è npx -y @ship-safe/mcp@0.6.4.
Nel formato JSON mcpServers, letto da molti client MCP desktop e per editor di codice, la voce si presenta così (segnaposto tra parentesi angolari):
{
"mcpServers": {
"scanner": {
"command": "npx",
"args": [
"-y",
"@ship-safe/mcp@0.6.4"
]
}
}
}Ricavato dalla voce del registro; la verifica live riportata sopra mostra solo se l’endpoint ha risposto. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server della categoria sviluppo
| Server | Esecuzione |
|---|---|
| ShipDappDeploy Dockerized apps to Akash devnet with ShipDapp MCP build, deploy, update, and logs tools. | Remoto · SSEVerifica live: ✓ SSE raggiungibile |
| ShipedDeploy AI-generated HTML/CSS/JS to instant public HTTPS URLs from any MCP-compatible agent. | Remoto · HTTPVerifica live: ✓ handshake |
| ShiplyPublish any app in one call: SQL database, functions, email, and a custom domain. Flat price. | Remoto · HTTPVerifica live: ✓ handshake |
| shippp.aiDeterministic Chakra UI code from your Shippp design files, straight into your IDE agent. | Locale · stdio |
| ShipStaticDeploy static websites from AI agents. Free at mcp.shipstatic.com - no install, no signup. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Shipswiftcomponents MCPA paid remote MCP for ShipSwift, built to return verdicts, receipts, usage logs, and audit-ready JSO. | Remoto · HTTPVerifica live: ✗ nessun handshake |
| ShodanMCP server for Shodan API - device search, IP lookup, DNS, and CVE/CPE queries. | Locale · stdio |
| Shoon A2A Trust Services (pilot)Five trust services for agents: claim checks, citation audits, extraction, tripwires, work audits. | Remoto · HTTPVerifica live: ✓ handshake |