Developer · Remote MCP server

ShipSafe — Independent security verification

Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access.

Visit ShipSafe — Independent security verification's website

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
co.ship-safe/scanner
Version
0.6.4
Status
Active
Category
developer
Transport
Streamable HTTP, stdio (local process)
Package
npm
Published
2026-09-28
Updated
2026-09-28
Publisher
co.ship-safe
Website
ship-safe.co
Source
Registry API entry

Remote endpoints

TransportURLHeaders declared
Streamable HTTPhttps://ship-safe.co/api/mcpAuthorization (required, secret)

Packages

RegistryPackageVersionTransportEnvironment variables
npmruntime: npx@ship-safe/mcp0.6.4stdioNone declared

How to connect ShipSafe — Independent security verification

ShipSafe — Independent security verification is a remote MCP server: there is nothing to install. Its endpoint is https://ship-safe.co/api/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.

The registry entry declares an HTTP header for the connection: Authorization (required, secret). A secret header usually carries an API key or token issued by the service; clients that accept custom headers set it with the server's URL.

It can also run locally from a Node.js package published to the npm registry: @ship-safe/mcp version 0.6.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @ship-safe/mcp@0.6.4.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "scanner": {
      "command": "npx",
      "args": [
        "-y",
        "@ship-safe/mcp@0.6.4"
      ]
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More developer servers

All 6,250 →
ServerRunsEndpoint or package
ShipedDeploy AI-generated HTML/CSS/JS to instant public HTTPS URLs from any MCP-compatible agent.Remote · HTTPshiped.app
ShipkitUnified app publishing MCP Server for Google Play, App Store, and 10+ Chinese stores.Local · stdionpm: @readmigo/shipkit-mcp
ShiplyPublish any app in one call: SQL database, functions, email, and a custom domain. Flat price.Remote · HTTPshiply.now
shippp.aiDeterministic Chakra UI code from your Shippp design files, straight into your IDE agent.Local · stdionpm: @shippp/mcp
ShipScreens MCP ServerUse this for agent inspect/plan/import/verify/stage store screenshots; not translation-only.Local · stdionpm: shipscreens
ShipStaticDeploy static websites from AI agents. Free at mcp.shipstatic.com — no install, no signup.Remote & Local · HTTP, stdiomcp.shipstatic.com
Shipswiftcomponents MCPA paid remote MCP for ShipSwift, built to return verdicts, receipts, usage logs, and audit-ready JSO.Remote · HTTPshipswiftcomponents.clauxel.com
ShotPulledEspresso dialing: log a shot, say how it tasted, get one change in your grinder's own clicks.Remote · HTTPmcp.shotpulled.com