PluginBench
MCP Server

ShipSafe — Independent security verification MCP Server

co.ship-safe/scanner

What is the ShipSafe — Independent security verification MCP server?

Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access.

How to install ShipSafe — Independent security verification

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • Authorization
    required
    secret

    Bearer token from https://ship-safe.co/settings — the same token the ShipSafe CLI uses.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "scanner": {
      "command": "npx",
      "args": [
        "-y",
        "@ship-safe/mcp"
      ],
      "env": {
        "Authorization": "<YOUR_AUTHORIZATION>"
      }
    }
  }
}

Related MCP servers

Verify a SickSlip doctor's note by Document ID; states served, pricing, physician NPI. Read-only.

SEC EDGAR crypto filing radar MCP with x402-paid Base USDC data URLs.

1
View repository →

Search and fetch skills from your org's Skills and Agents catalog. Bearer token required.

1
JavaScript
MIT
View repository →

Web search, fetch, extract, and research for AI agents. Markdown output + AI-synthesized answers.

Renamed to AI Crypto Sniper. Use com.aicryptosniper/ai-crypto-sniper-mcp instead.

View repository →

Read-only catalogue of the Spark apps: what each one does, its stack, and where it runs.