Developer · Remote MCP server
ShipSafe — Independent security verification
Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access.
Visit ShipSafe — Independent security verification's website
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
co.ship-safe/scanner- Version
- 0.6.4
- Status
- Active
- Category
- developer
- Transport
- Streamable HTTP, stdio (local process)
- Package
- npm
- Published
- 2026-09-28
- Updated
- 2026-09-28
- Publisher
- co.ship-safe
- Website
- ship-safe.co
- Source
- Registry API entry
Remote endpoints
| Transport | URL | Headers declared |
|---|---|---|
| Streamable HTTP | https://ship-safe.co/api/mcp | Authorization (required, secret) |
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npmruntime: npx | @ship-safe/mcp | 0.6.4 | stdio |
How to connect ShipSafe — Independent security verification
ShipSafe — Independent security verification is a remote MCP server: there is nothing to install. Its endpoint is https://ship-safe.co/api/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.
The registry entry declares an HTTP header for the connection: Authorization (required, secret). A secret header usually carries an API key or token issued by the service; clients that accept custom headers set it with the server's URL.
It can also run locally from a Node.js package published to the npm registry: @ship-safe/mcp version 0.6.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @ship-safe/mcp@0.6.4.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"scanner": {
"command": "npx",
"args": [
"-y",
"@ship-safe/mcp@0.6.4"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More developer servers
| Server | Runs |
|---|---|
| ShipedDeploy AI-generated HTML/CSS/JS to instant public HTTPS URLs from any MCP-compatible agent. | Remote · HTTP |
| ShipkitUnified app publishing MCP Server for Google Play, App Store, and 10+ Chinese stores. | Local · stdio |
| ShiplyPublish any app in one call: SQL database, functions, email, and a custom domain. Flat price. | Remote · HTTP |
| shippp.aiDeterministic Chakra UI code from your Shippp design files, straight into your IDE agent. | Local · stdio |
| ShipScreens MCP ServerUse this for agent inspect/plan/import/verify/stage store screenshots; not translation-only. | Local · stdio |
| ShipStaticDeploy static websites from AI agents. Free at mcp.shipstatic.com — no install, no signup. | Remote & Local · HTTP, stdio |
| Shipswiftcomponents MCPA paid remote MCP for ShipSwift, built to return verdicts, receipts, usage logs, and audit-ready JSO. | Remote · HTTP |
| ShotPulledEspresso dialing: log a shot, say how it tasted, get one change in your grinder's own clicks. | Remote · HTTP |