Run it where you work.
Scan any repository from the terminal without creating an account or uploading the entire codebase.
- One-command setup
- Local-first scanning
- CI-ready output

Local scans, PR fixes, and cloud history when your team needs it.
Start with a local scan. Add deeper context and automation only when you need it.
Scan any repository from the terminal without creating an account or uploading the entire codebase.

Move past a flat list of warnings. Ship Safe groups findings by severity, confidence, and real exploitability.

PR Guardian puts the finding, affected code, and fix guidance inside the review your team is already reading.

Security Intelligence connects advisories and exploit context to the technologies inside your stack.
Compose specialized Hermes agents for deploy checks, investigation, monitoring, and incident response. You define the playbook; Ship Safe coordinates the work.
Use Kimi K3-powered adversarial analysis to probe tool calls, long-context behavior, and agent boundaries.

No account required for local scans.
The scanner stays free. Pro adds the hosted tools that help teams keep moving.
Unlimited local scans and CI-ready security output.
Run locallyHosted history, private repos, reports, and PR Guardian.
Start Pro--no-ai to keep scanning fully local. See the security and data-flow details.scanning agent configs for vulnerabilities before deploy is exactly the gap in the current toolchain. most teams don't even audit their MCP tool permissions until something breaks in prod. security-left for agents is a real market.Builder
Interesting!Cofounder and Lead Engineer, Hermes Agent at Nous Research
Public posts shown with attribution. Select a card to view the original post on X.
Ship Safe is MIT open source. Add agents, MCP rules, fixtures, docs, CI examples, and dashboard improvements with a focused contributor path.
Run locally for free, then add the cloud when your team needs history and automation.