About this integration
Read-only Shipcheck launch-risk scans for authorized JS, TS, and MCP repos.
- Transport
- stdio
- Authentication
- none
- Initial setup
- none
- Runtime
- unattended
- Evidence
- documented
- Version
- 0.1.12
- Package
- shipcheck-mcp
- Last compatibility test
- Not independently tested
Connect your agent
shipcheck-mcpUse only on repositories the operator owns or is authorized to inspect. The publisher characterizes this as defensive static analysis rather than a penetration test. No scan was run.
Capabilities: repository static analysis, launch-risk scanning, SARIF output, MCP configuration checks
Connected profiles
Additional details
io.github.TateLyman/shipcheck-mcp
Source ↗ · Checked 2026-09-170.1.12
Source ↗ · Checked 2026-09-17CC0-1.0; package licenses are separate
Source ↗ · Checked 2026-09-17npm
Source ↗ · Checked 2026-09-17shipcheck-mcp
Source ↗ · Checked 2026-09-200.1.12
Source ↗ · Checked 2026-09-20The client launches a local stdio command, and the publisher states that scans read project files without modifying the repository or executing project code.
Source ↗ · Checked 2026-09-20The publisher states that the scanner does not require network access; no credentials are documented in the MCP configuration.
Source ↗ · Checked 2026-09-20The documented configuration launches shipcheck-mcp with npx over stdio.
Source ↗ · Checked 2026-09-20Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-20