New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

shipscanner

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

shipscanner

The credit score for AI-generated code. Scan any GitHub repo from your terminal.

latest
Source
npmnpm
Version
0.1.1
Version published
Maintainers
1
Created
Source

ShipScanner CLI

The credit score for AI-generated code. Scan any GitHub repo from your terminal in seconds.

Score range: 300-850 (like a credit score). Grades: A+ through F.

7 scanners. One score. Works with AI coding agents.

Quick Start

# Scan any GitHub repo
npx shipscanner scan https://github.com/owner/repo

# Shorthand works too
npx shipscanner scan owner/repo

Install

npm i -g shipscanner

Commands

Scan a repository

# Basic scan
shipscanner scan owner/repo

# Specify branch
shipscanner scan owner/repo --branch develop

# JSON output (for AI agents, CI pipelines)
shipscanner scan owner/repo --json

# Fail if score is below threshold (CI quality gate)
shipscanner scan owner/repo --threshold 700

Authentication

Free tier: 5 scans/hour. Authenticate for higher limits and private repo access.

# Set your API key (get one at shipscanner.dev/settings)
shipscanner login --key sk_your_api_key

# Check auth status
shipscanner whoami

# Remove stored key
shipscanner logout

Other commands

# Check status of a running scan
shipscanner status <scan-id>

# View/update config
shipscanner config
shipscanner config --api-url https://shipscanner.dev

Output

  ShipScanner Report
  owner/repo (main)

  Score: 720 / 850  (A)
  ████████████████████████████░░░░░░░░░░░░
  300──────────────────────────────────850

  Security               ████████████░░░  240/300  (80%)  3 issues
  Secrets & Credentials  ███████████████  200/200  (100%) clean
  Dependencies           ██████████░░░░░  100/150  (67%)  8 issues
  Code Quality           ████████████░░░  82/100   (82%)  5 issues
  Best Practices         ███████████████  98/100   (98%)  1 issues

  Critical: 0  High: 2  Medium: 5  Low: 10

  Full report: https://shipscanner.dev/report/abc123

For AI Agents

ShipScanner is built for the agent economy. AI coding agents can call it before committing code.

# JSON output for machine consumption
npx shipscanner scan owner/repo --json

# Use as a quality gate (exit code 1 if below threshold)
npx shipscanner scan owner/repo --json --threshold 600

Environment Variables

SHIPSCANNER_API_KEY=sk_...    # API key (alternative to login)
SHIPSCANNER_API_URL=https://shipscanner.dev  # API endpoint

What It Scans

ScannerCategoryWhat it checks
SemgrepSecuritySAST - SQL injection, XSS, etc.
GitleaksSecretsHardcoded API keys, tokens, passwords
TrivyDependenciesKnown CVEs in packages
ESLintQualityCode smells, anti-patterns
jscpdQualityCopy-paste / code duplication
LizardQualityCyclomatic complexity
RepocheckBest PracticesTests, CI/CD, LICENSE, README, .gitignore
  • Website: shipscanner.dev
  • GitHub Action: shipscanner/action

License

MIT

Keywords

shipscanner

FAQs

Package last updated on 20 Mar 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts