{"_id":"ship-safe","_rev":"51-e54f7b5fcdaa11100ecbd8a0aba32a07","name":"ship-safe","dist-tags":{"latest":"10.1.0"},"versions":{"1.0.0":{"name":"ship-safe","version":"1.0.0","keywords":["security","secrets","scanner","devops","devsecops","api-keys","gitignore","indie-hacker","vibe-coding","mvp","cli"],"author":"","license":"MIT","_id":"ship-safe@1.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"1cebff8f03fd705e4478106a652addd135fea599","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-1.0.0.tgz","fileCount":13,"integrity":"sha512-ueY6XtzbyHjviW6DYvAXhICS+iyaByOhKOBrsGQSO+xb4qH858hMHX267xFafjE43KlRy9j2TEBpS1HGG8Rm6g==","signatures":[{"sig":"MEYCIQC1gB/IIxXbNv0Le05SbvU8iE0ypyWGsFkUi2sSOmNobwIhAPrbYe5VxlvrI0Itv4bT7fx18bd+eTIhHjLLdXV9eBnP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71120},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"e42aecbf0b1f11264a044632a41202574d389483","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"Security toolkit for vibe coders and indie hackers. Secure your MVP in 5 minutes.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","glob":"^10.3.10","chalk":"^5.3.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_1.0.0_1770105352651_0.33734333574641595","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"ship-safe","version":"1.0.1","keywords":["security","secrets","scanner","devops","devsecops","api-keys","gitignore","indie-hacker","vibe-coding","mvp","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@1.0.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"ecb3133c2df678b30df194869d6d8258b3d2f57c","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-1.0.1.tgz","fileCount":15,"integrity":"sha512-5+V2CNv2Xr5xgOs5uFv2fjlY1qXhmJF4lW1AcaNGbTYaucQ4d6RIEMa0YTlMX2nn3X+uEtWFHZ6O7CFLCj3v7Q==","signatures":[{"sig":"MEUCIQDY2D7wkI18NlnaSHRSTBNbJme1IAmsxbRzst4YhriMbwIgP/MPyu7tiJyfZ8WmRkO5USNJk75Sc6teAKN4LWwOlDY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":77893},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b395025f64068db7cf1181a5bd646e2f0618a58a","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"Security toolkit for vibe coders and indie hackers. Secure your MVP in 5 minutes.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","glob":"^10.3.10","chalk":"^5.3.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_1.0.1_1770106400817_0.22472499731054674","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"ship-safe","version":"2.0.0","keywords":["security","secrets","scanner","devops","devsecops","api-keys","gitignore","indie-hacker","vibe-coding","mvp","cli","supabase","firebase","llm-security","prompt-injection","rate-limiting","owasp","jwt","cors","rls"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@2.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"63e30431d7233ac2866a038697ca82235936c19f","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-2.0.0.tgz","fileCount":30,"integrity":"sha512-dYDibDgWdU+XbpO/9hI61hY0VeFiHobGbZCFOHFAI7S/9ZhXBkAtP4R7ZmGUfE8UGjqDDCyQRm1ugQ1T+Yxeyw==","signatures":[{"sig":"MEYCIQC/y7n5yLYHY1dVCjJApIeTZxrWcy51dQLrWYMEe2Kq0AIhAKh9uSkE3g3X7xbVkTxhdYQ2zYuN4tuYEyj8tnX6v1Jc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":211503},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"5d5c6faf61cc7c768ec6e2569e39038a21eaf74c","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"Security toolkit for vibe coders and indie hackers. Secure your MVP in 5 minutes.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","glob":"^10.3.10","chalk":"^5.3.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_2.0.0_1770228688291_0.38567879362360946","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"ship-safe","version":"3.0.0","keywords":["security","secrets","scanner","devops","devsecops","api-keys","gitignore","indie-hacker","vibe-coding","mvp","cli","supabase","firebase","llm-security","prompt-injection","rate-limiting","owasp","jwt","cors","rls"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@3.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"cc7831762f98648596abe06313ca2ca64a283e28","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-3.0.0.tgz","fileCount":35,"integrity":"sha512-qHxxSpig1p9ivIVGIf8gE5xL83DRCHG2idgZ1IK1YmnuXek+V0zI89BrmSOIO84rUz513pGRWGGJ5W0m19RRGQ==","signatures":[{"sig":"MEYCIQD1ddoAhpMnQ9zbqJK1H5CdAOHOLfv2b1vU+6WQPHL8hgIhAOAj4wST5Z5AS7d8eVO9QiJ+gcoDU3Azq1uONdhKkRmh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":255694},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"13d79914c69cda5a075365dfe1e7497fe846ebec","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"Security toolkit for vibe coders and indie hackers. Secure your MVP in 5 minutes.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","glob":"^10.3.10","chalk":"^5.3.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_3.0.0_1771366551696_0.05848517487077709","host":"s3://npm-registry-packages-npm-production"}},"3.1.0":{"name":"ship-safe","version":"3.1.0","keywords":["security","secrets","scanner","devops","devsecops","api-keys","gitignore","indie-hacker","vibe-coding","mvp","cli","supabase","firebase","llm-security","prompt-injection","rate-limiting","owasp","jwt","cors","rls"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@3.1.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"cc8f5a4e29e08e773a57c9c556415d3d9a73b866","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-3.1.0.tgz","fileCount":37,"integrity":"sha512-G11LhRVyIhaqcmG+I4JhVRdb9OiS6NPGB4up8hDT6+S9jp1zzZtStiJBKqh5uM8A/YtpxRz2pwWAyIz/qV2lhA==","signatures":[{"sig":"MEYCIQCiy7aAL2DJ0FvYzJ8+zyeQVCaZclWFcIIiJtqe8ZynnQIhALPv8UroLNjmi/8nlmkSjRX8F1Cf4z4b0Tc0w82l7gFc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":302297},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"f1a1fd785b034ca2d95ea7d44dbfaf887806c319","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"Security toolkit for vibe coders and indie hackers. Secure your MVP in 5 minutes.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","glob":"^10.3.10","chalk":"^5.3.0","commander":"^12.1.0","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_3.1.0_1771390747208_0.5597617147046412","host":"s3://npm-registry-packages-npm-production"}},"3.2.0":{"name":"ship-safe","version":"3.2.0","keywords":["security","secrets","scanner","devops","devsecops","api-keys","gitignore","indie-hacker","vibe-coding","mvp","cli","supabase","firebase","llm-security","prompt-injection","rate-limiting","owasp","jwt","cors","rls"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@3.2.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"8023379535b5665f31da8b28e09b79482825d034","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-3.2.0.tgz","fileCount":40,"integrity":"sha512-xruYcvkw6eAJ9ibhumYYB9qWZxFt8QZ2B2RwWla6LG/KhZYYdpLP3RrYVJcolCoGnn52mlzt1NcbQWqslKfkKA==","signatures":[{"sig":"MEUCICILv7x9Bg/+uMIiFg6PxnNlDddgU4Xc+QK/n1Af8BNEAiEAgc0avB/GTcudLOnvnK1keJUfBM4dHCZhI1tlkWxjKiY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":388410},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"8a3fc9b652c8326955026f428e50fdae5c5810ff","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"Security toolkit for vibe coders and indie hackers. Secure your MVP in 5 minutes.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_3.2.0_1771495694663_0.8008778707406923","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"name":"ship-safe","version":"4.0.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@4.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"3877965fd610dc9bb2694a888d2b9487fe74d527","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-4.0.0.tgz","fileCount":62,"integrity":"sha512-kiiZv7DwpryJ2eP+R4mMg2ZtJHGEnb2XuwreVRCPPePBZRKbhIb/SmgETBvUIpxocpwSCj17zJGqsOKm2jCXTw==","signatures":[{"sig":"MEQCIDWwuxnzlZGttxv9R003+kdeqzSw4FWld52SalPLSAEMAiAptbJ7GUQlMMf/C58LQqfNA8OMPJm+KvqmPikJiQ+Srw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":608745},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"547cf8d79cee7e2ab4463cd4a8929cc6ff341407","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 12 agents scan 50+ attack classes. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_4.0.0_1772176774646_0.5737298768857013","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"ship-safe","version":"4.1.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@4.1.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"3e385b41255f5b3d3cc470e55e68036eca362711","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-4.1.0.tgz","fileCount":63,"integrity":"sha512-DzT7RJiIsXqCEc8MkEG6Ubc2DObsDmGf2LLuHIp1hWaJ5nmULu4cx8cJbAcs/BIMuDXzcRUGU6FTl21DpoJBcQ==","signatures":[{"sig":"MEUCIQD5rb/0Y7jARM62E4A9XA9+nN6Ohj2NTlJUcyWqvxNURQIgKMbAaIAkJLHFF4JXNDPuyAvmLWrp2VUehRrV0mHhS3s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":626469},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"a07df921edb4df5a311dfee3119d5cc20eac2c6f","scripts":{"lint":"eslint cli/","test":"node --test","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 12 agents scan 50+ attack classes. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_4.1.0_1772214385424_0.7514003302858392","host":"s3://npm-registry-packages-npm-production"}},"4.2.0":{"name":"ship-safe","version":"4.2.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@4.2.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"ba58a8b3424de3e69344b6070cf74e50de85cbcf","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-4.2.0.tgz","fileCount":65,"integrity":"sha512-gFnZ2RhtCg+WX/RjdwCYfqUG4lsqKHuJ8JF/kvKZMJxTfwsWpdyB+MWMmTykJJX8ylg6GhM3/XsolFLEd9utrQ==","signatures":[{"sig":"MEYCIQCJ5gWgSXPQr+XnMcqBnEXq55cMLZpPG2CBsVAkIeFTXAIhAK25O4P/vcQ2KacjBJpzF7oArKCEx3qIPqn7Ym/VDyuo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":675382},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b93e0b36b112fb2e4fce42c66ea9c6081c567160","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 12 agents scan 50+ attack classes. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_4.2.0_1772689443633_0.6894080153940061","host":"s3://npm-registry-packages-npm-production"}},"4.3.0":{"name":"ship-safe","version":"4.3.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@4.3.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"449634a590aeccef8ab08c63238922500562b725","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-4.3.0.tgz","fileCount":69,"integrity":"sha512-dSJ4b8YsvEJ24fsIuW63kD0prTvZZWQtAGa90XvdhNFtfOVosaLYDaoTLHe9loCanKPqwtrglht1lpwQllHDrw==","signatures":[{"sig":"MEUCICoihlodCyOeBQVNJjU/GoK6HM2P4q7T1rs9uIojYWATAiEA8coPl5Tmg4MXC2nI4bh0IL49gSHcxPGNGd9ibrfHAa4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":724224},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b8294a4bcb65732896aa5dc83a730029dafb14b4","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 12 agents scan 50+ attack classes. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_4.3.0_1772994493427_0.5991424641085519","host":"s3://npm-registry-packages-npm-production"}},"5.0.0":{"name":"ship-safe","version":"5.0.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@5.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"b8a4923425415ebe0a4bb79d892a9d57f6eb0986","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-5.0.0.tgz","fileCount":77,"integrity":"sha512-wWQ6jmqNm2RiY2vLdPfmqFYOnzlaAsCC777vV3bbLwfkctKkvGXULzqEw0GWCgiH7V1ri6ujKpTpEx1zQYyvJg==","signatures":[{"sig":"MEQCICEgxQSwoQ1afB9ZLi+l+cMlbtKOvGll9VhdpiivBX2sAiAcaqzI04lnZNgvvZlXuxErod4hAcnfBu1sqhK7yn/xiQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":865173},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"f2aa03afa1c655d25ea1b548b59ecb9da66f0a63","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 16 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_5.0.0_1773723268864_0.41521657198555584","host":"s3://npm-registry-packages-npm-production"}},"5.0.1":{"name":"ship-safe","version":"5.0.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@5.0.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"2670c6c481f7fce6f7a1cdfed6ad9fd3506af40a","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-5.0.1.tgz","fileCount":77,"integrity":"sha512-LwsmHp0mVhenqCh+Bfv6CSCc6yXYfKy+glA3pT+6+ZUhUltEiEzLQPOtdPfX89zIRd5njgydyUjcbidikkmZIA==","signatures":[{"sig":"MEYCIQCjPRTGN2YYqIUBhGdP1GFShnXtZZNPnD0L4xqs4buLNwIhAI6CAWRhmVuFVQF/TKYtEAraR++YDl48AQoVwAD1MPkU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":871863},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"008b76408015c41503f1ea2bc4beee86a933c5e7","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 16 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_5.0.1_1773729944716_0.2747044358139883","host":"s3://npm-registry-packages-npm-production"}},"6.0.0":{"name":"ship-safe","version":"6.0.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@6.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"dbc5aee704a4438677f3967796e36095d31939ab","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-6.0.0.tgz","fileCount":82,"integrity":"sha512-8bFMmy+GwUNMqmwiYvvqjrahmtyman25L0+bIdF1xDwzCSAvUKZfZz5FCFeB+ZgyKAs1dSJFNB90Q0VCRxmPLA==","signatures":[{"sig":"MEQCIFvQSkH2Prg1B1BVOx43dHYh7p+pg0OWiq0IHwLYX5VOAiA2yczyyTYSzRyzcS77u8vrX6oXrZ/dMD0KlY7kiVvUTA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":957181},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"ef44f20e58ce4f1f375d0d400cf22fc0ac45950e","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 17 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_6.0.0_1774238494368_0.2550874082119683","host":"s3://npm-registry-packages-npm-production"}},"6.1.0":{"name":"ship-safe","version":"6.1.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@6.1.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"1610b3215537a014aa2a9f0a1f68df9dad2a21e2","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-6.1.0.tgz","fileCount":91,"integrity":"sha512-0QhowqHb0iGN1zBMEV1oiS/XbmNwflmdtmFmcB+3bjXaQhnwvnapGk0RyDz0TwpHmro9jT98cWmpRQjELXIftw==","signatures":[{"sig":"MEQCIHIczvFQSQssrqOYFwvVO40omR4aUxFwvmhNu23QQZEvAiA81U/WWLk36JRLZT3t14ADuD1i3Q6E9Clf33vx6wtMvA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1054734},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b6a823661053d046bedb2321257d092c230619fe","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 18 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_6.1.0_1774316813505_0.01950716961341792","host":"s3://npm-registry-packages-npm-production"}},"6.1.1":{"name":"ship-safe","version":"6.1.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@6.1.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"87fb65fdd82f62f9eb87d8c3936d857717b7f990","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-6.1.1.tgz","fileCount":90,"integrity":"sha512-8qWCWL2Qtrqbh4dgd3JVYQHbnjPkubvkbqnP1xpTImR8Z6T0TwyDFyV48Kz9NV2WtmT28mkpUzfCMzEsagQADQ==","signatures":[{"sig":"MEUCIQDYr71Q4jpvco5h8+A/0jgWxzP+tfEYwZ9nr/7fw2jU5AIgJKhsZMGfKVqj2/MwAnMBfSo8zyTDGbMlGqhHvl5bXbc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1006657},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"680706d1270160f0a31781dc2201da65fa47fd15","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.6.2","description":"AI-powered multi-agent security platform. 18 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_6.1.1_1774578164937_0.8935565060059523","host":"s3://npm-registry-packages-npm-production"}},"6.2.0":{"name":"ship-safe","version":"6.2.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@6.2.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"957b99df0e5908dc9159a14ad9cc4c505a78a202","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-6.2.0.tgz","fileCount":93,"integrity":"sha512-IdVR/s+jbsffZaR4zzsEgYk5VOFJ3L0JqTYScsiOsUoMD3DO6rN3+HXsfPLNqNnNUxXlKmFKE2arRSCu7gQlvQ==","signatures":[{"sig":"MEUCIH0sm8JCvouARCom49+j6/WKaspTympIu0SCWvYN7aSmAiEAirW99D62BS+CPDQ6upVxV6f4jtfpxhU2p0Og/YYwpJ8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@6.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1035347},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"017a018cbdb744d0b7f694909997b7d4d5eedc24","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 18 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_6.2.0_1775069628022_0.8485472594992007","host":"s3://npm-registry-packages-npm-production"}},"6.3.0":{"name":"ship-safe","version":"6.3.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@6.3.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"781263b603e7726ba327a05c7644332c3210675f","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-6.3.0.tgz","fileCount":95,"integrity":"sha512-vCEE2bS4Tvb4oY5gri3DA7Q/ouN3tWtTyBlBF0CB7ZABpfN/tFE4ezZVT+imHAHJnZHyYkoSrucaaiFlsKP3LQ==","signatures":[{"sig":"MEYCIQCkpvZoha+o9zuhGwUKQZjgPLiVozT3MNPMRubdfYqUNQIhAOuh4eFET5sPySDC/J49+hjpVcanPh74mrozMIPrjlJ5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@6.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1053691},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"68e1568fafe45fc530da336eda641416b8033ec0","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 18 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_6.3.0_1775076146408_0.013523542494303653","host":"s3://npm-registry-packages-npm-production"}},"6.4.0":{"name":"ship-safe","version":"6.4.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@6.4.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"594edc1a1aa38b9ce72b4af5f404ac1216eab140","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-6.4.0.tgz","fileCount":96,"integrity":"sha512-HsMCPXhN4LSQMykupBTTpaobWceH3n7X+TVIBpywfdJU5Kqb/HpPqV34F9gDGnmWyeHIc1TyTatkLDPTV3dTCQ==","signatures":[{"sig":"MEQCIF4zAAVImHCP247pSnP253TjPrKqDVsK2j5+WAaLntU2AiB7Bq/qZpF8cOC8aCAOifw08zyby542cobWE+Aor81pGw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@6.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1088381},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"4dbf6241337b0b714ce1871d4cd8efc1db2eb0af","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 18 agents scan 80+ attack classes with LLM-powered deep analysis. Red team your code before attackers do.","directories":{},"_nodeVersion":"20.20.1","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_6.4.0_1775104283655_0.6664882425006022","host":"s3://npm-registry-packages-npm-production"}},"7.0.0":{"name":"ship-safe","version":"7.0.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@7.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"9ab4e4753cfb388a8d9c74445fc03b3228ec9d0f","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-7.0.0.tgz","fileCount":98,"integrity":"sha512-1vvU6Cv4pRcNaH0dcz2dGb83lJTA5ZiYI+L/b7TLYuTyPwvk7m53Bpohd0J41Qe22LimY8oARzn1Zh/Nzw+ewg==","signatures":[{"sig":"MEUCIGuKfQ9B8tCddKImzkf5gZyD4jCsLnWHrASln4/Lj+QGAiEA7TNykZfO6Kdhhb2ROObgnVg2gX59zrtjYUTYndIVpHs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@7.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1133754},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b3ca118503b7f6dda32ff8c71d8bfc36681bf1e9","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 19 agents scan 80+ attack classes with LLM-powered deep analysis, OWASP Agentic AI Top 10 mapping, memory poisoning detection, and live advisory feeds. Red team your code before attackers do.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_7.0.0_1775521815342_0.8755437676979132","host":"s3://npm-registry-packages-npm-production"}},"8.0.0":{"name":"ship-safe","version":"8.0.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@8.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"a6279c21d69f0a45ea0c570d5c02c6a7ecdb7245","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-8.0.0.tgz","fileCount":107,"integrity":"sha512-55fPJUy/fo7HsppZC3Zgv0oABvn6/EhrPS1ng1/pMlczhUePiAPTXzLsu4rS8kDeo7eQn/yeZ4Z4yv7iukNBUw==","signatures":[{"sig":"MEQCIAw//TGkCUEgFIEEw6e2Q9ocBtaEjU+3QEQ9u6frnanXAiAKlbnygX+0uR1bg1I4JiHoSYBi1ab8hAhBt1jcGqkrjA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@8.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1301641},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"4c2c6d4004a586bf137344dd005d437db69d4693","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 22 agents scan 80+ attack classes including Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, and agent attestation. Ship Safe × Hermes Agent.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_8.0.0_1775917252767_0.33979948446456354","host":"s3://npm-registry-packages-npm-production"}},"9.0.0":{"name":"ship-safe","version":"9.0.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"d5a2935441c0e1ddcf1f7b23a8ac06c738369099","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.0.0.tgz","fileCount":107,"integrity":"sha512-ezvKgZziWmUfkf0R7FKwnHLUAWTzUUw8rOj3WDwkpJCN3VETG0x8SnOl11IDpmc19yC2OzpWD8x8/zgqRvoC5A==","signatures":[{"sig":"MEUCIQCTFx6yptn9pJufwguglVmhVTKN38fhZAFvGYw4QI30+AIgApBeXuN2U/JlscKF0hK3BEUVWHPA04gnoQMqUYMOx7w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1339061},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"22be352cd22fa3bdfdf2bcb6b072a64c55c25767","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 22 agents scan 80+ attack classes including Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, and agent attestation. Ship Safe × Hermes Agent.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.0.0_1776262450804_0.9308919660989696","host":"s3://npm-registry-packages-npm-production"}},"9.1.0":{"name":"ship-safe","version":"9.1.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.1.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"b3fa9551d5efb2ff527673f659931d3dd6e56219","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.1.0.tgz","fileCount":108,"integrity":"sha512-1jLYxdAdTN4MACLNKkpuQdyNR7QoYncFN8eECiMszJTm9qlwqeaEO7/cWLYmZHSgpRWOFsDEWMhf9lCFqkzrtA==","signatures":[{"sig":"MEYCIQCS73/JJOE3QHMhaIQqvAQeGZyznG/s2N5Y+OcEBQZguwIhAISt1UR9ImNn20MWLC2wshQuLlKol3OZP4PUrqTaQOqU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1362850},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"7f91fc910fed8fc0f7157fb3b28f74efd3d69e76","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.1.0_1776723962576_0.9129804243500215","host":"s3://npm-registry-packages-npm-production"}},"9.1.1":{"name":"ship-safe","version":"9.1.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.1.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"f1ccc97a6605e802dc31bb103ee5dab416ef8f63","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.1.1.tgz","fileCount":110,"integrity":"sha512-deJWbrf9xVATbqV8DiJwdsCtSAOhf9Ltyob1+3udlUiYqeSjir/YRK6jS55tPUyjJu38Kko9gCnVXtFA6TcmJw==","signatures":[{"sig":"MEQCIAmelQijrURSydjaNS6NLAnhQc7N+hSZLqEUhcMtLjZqAiAF7kwY51nve3lFfEG4tkfDPltFYO5louKuiPy2rzXTwg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1401292},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"d1fcfc3f15d424c600131321005260959164849d","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.1.1_1776724173993_0.7002364984716072","host":"s3://npm-registry-packages-npm-production"}},"9.1.2":{"name":"ship-safe","version":"9.1.2","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.1.2","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"9c7a52e72b8da39d2ade6c1186cb65a3d2dd0d25","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.1.2.tgz","fileCount":111,"integrity":"sha512-1XawytMrhtwk+V1xZDTN8mes1shJqq80xHOGhwd+xmN300OoPU++aGZQm4T2IUMohavKFcXsrOlf5SX1Utdo2A==","signatures":[{"sig":"MEQCIBFU38tpYbQ9Newxc08zS6xjMLqJ1X3rSSEGNq0Dw38IAiB2FlyRn93YeVAiqto/kdw1lW8A9FdXTjooTt1PJ6nhkQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1420793},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"67bdfd7432b7a6bf4617105e9b52d811f8871e47","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.1.2_1777084671936_0.421496433911436","host":"s3://npm-registry-packages-npm-production"}},"9.2.0":{"name":"ship-safe","version":"9.2.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.2.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"b2a67eb93fa3ae634f342e9cd67f0885f37947fa","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.2.0.tgz","fileCount":114,"integrity":"sha512-H3RbMCNOwAG9PCh4v4vjzSdXhmQy2UbYRE5M7B+xr1+74sqOpM18imlFZ0FjkSmWZhyNm8yQTBfIX4VU8ISyMw==","signatures":[{"sig":"MEUCIQDcmIrg8lnYosCha5TBFDItDV5SrdR91YrKxDQmhdEh6QIgEEfnjVO0oqx4JNeQgYz/PaJf7MYBh+Uv8JHWdVctN50=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1486050},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"6ae066c31bae087ddf78c12f596351ed7f5bac1e","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.2.0_1777221716980_0.44188412059048354","host":"s3://npm-registry-packages-npm-production"}},"9.2.1":{"name":"ship-safe","version":"9.2.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.2.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"3549f8a7193541242140aeb3fefdc31ac769945c","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.2.1.tgz","fileCount":114,"integrity":"sha512-QucbBxzhv/oer4NgKCnCl4xXvgxFy+q2hgWBTkqCAEPCqWMvwbdPvSe5RFN7l2R16dyG8Vgyj2O5uI7uONCs8g==","signatures":[{"sig":"MEQCIBx4S0dcPJylo6Y5O5fieuFc8bBRkC0Xp+QkEGwGDyf+AiASfap8Ue4wvHMYVoYptlUBM7Kxq7kb2VvO3C1dxxEYAQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1490455},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"3f09e7184470c2c1312bc48e3eb747179f612070","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.2.1_1777263183113_0.07680063359980016","host":"s3://npm-registry-packages-npm-production"}},"9.2.2":{"name":"ship-safe","version":"9.2.2","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.2.2","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"99da98889a1a0054d90b360d5636ce5c136ef69a","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.2.2.tgz","fileCount":116,"integrity":"sha512-zCMG0MTHuIPkGyL3iX68RTgCCRXIrr7pkBfLd4Rbs+HUDCVOM4ATjvgoefctqUFzBJkWprVkdM8eIJd4TKxa1Q==","signatures":[{"sig":"MEQCIFgbhgs5xkWQROWmTet18RqH1WjNpH+EAi0D1Q2oYXZuAiAQghCanKl0C/9qEs5xS/TEvYGRW4w9fjg1qUl3frPm/A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1797704},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"7b3591b58c6624a0e9e283c3f1fd486fca0b02ac","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.11.0","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.2.2_1777436311305_0.9795414200519421","host":"s3://npm-registry-packages-npm-production"}},"9.2.3":{"name":"ship-safe","version":"9.2.3","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.2.3","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"4091744a17577f44f4041b7db24415508732efc3","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.2.3.tgz","fileCount":117,"integrity":"sha512-OjJUOmheVM47e422Od8D8rDEpDTCQIqmTib8pYyhf/E/gEE6YpN2Ba6en9RpAz2eugqzKc/tnxKCd1awmeRK1Q==","signatures":[{"sig":"MEUCIH6vpRKpixJ5ANmEf7y7747Vc5X6GoDi2q4z1SO0HJhuAiEA+xkm3Zb2ZCkDpANiJAjRXhgjeF3W2K5YNLr9aPMinlk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1801862},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"7439c0cc2e6a37c5e4c4a8966ae95955627b1c1e","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"11.11.0","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.2.3_1777877161321_0.2872498928284113","host":"s3://npm-registry-packages-npm-production"}},"9.2.4":{"name":"ship-safe","version":"9.2.4","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.2.4","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"83e16efa64d4cde66bd59668426c761a477b980b","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.2.4.tgz","fileCount":115,"integrity":"sha512-jE6cs0RN12RcTrQTXf5mojCY3OcmrCllnvqI8F4knvYlAG9ZCcSXkyLtohujvbcDh9pPyOwPCRdbwNcQReRdDg==","signatures":[{"sig":"MEUCIBUmrAEqaP4nlnDIVUs+QKSXMAlukS/+a/WA0Fj63BQ8AiEAkke2nGLhdqKz/dixlWTgBzW6Je3+Sg5RPwqTK5w6UMo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.2.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1466359},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"9c7688b5b26ed37140801699dc45f64b62635ea6","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.2.4_1777936556391_0.6931379813290997","host":"s3://npm-registry-packages-npm-production"}},"9.3.0":{"name":"ship-safe","version":"9.3.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.3.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"8f1fb773edb39fdadd0606cea612c70d3924a88e","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.3.0.tgz","fileCount":115,"integrity":"sha512-9r3zSq4UBwJpvPG+IQ2ht+oOW/C+m3MWq1HCiQ5aG3HtX4MDsdIig4aX8bbvm5hw2SOy7GFyof8rpCzcjy7frw==","signatures":[{"sig":"MEQCIDy37o2exxaGLPYb6lpJBzBX5JezLOWqxIee1PGBBBKRAiAcsFmsIXn/+55rqoCxc7g28tFW8///SnOrP1MUoATdeg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1476129},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"834f76ad3d5a2903b88b5d0a46db6bfc55cbd34c","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.3.0_1778566255732_0.5339609484090768","host":"s3://npm-registry-packages-npm-production"}},"9.3.1":{"name":"ship-safe","version":"9.3.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.3.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"a9c143fae6b5059454a59c2ba508e15406706d8a","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.3.1.tgz","fileCount":115,"integrity":"sha512-7Q+F+Xgqip2/GMU29UMjqJrMRwizTZTeRfIGi4NfJGfk8MjnLWdAq825ot7Oe7/606DdDOY0XJpg5DaT1Ln62Q==","signatures":[{"sig":"MEQCIERervAWeRc9Xru5o4Nsle4aHoG7EfUcO0yvkJEQmKYXAiANlfWns5+tMy9HwhLXnIiCeC/4pRQBjdgzL3zx6D/V4A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1482426},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"cddf6e9aae34b74a0d8ff9a7da8533319bab9273","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.3.1_1779269469704_0.04852721149449257","host":"s3://npm-registry-packages-npm-production"}},"9.3.2":{"name":"ship-safe","version":"9.3.2","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.3.2","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"029f36eaafbed5b0ae92a334d9e780288511704d","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.3.2.tgz","fileCount":115,"integrity":"sha512-GROFpUqfz5H+i6dh98/M991nznswQQUFuIwSTd092Cq3JZS7TivpuRbuBkAnypyTV72n41YAQeKQndDwQkjSew==","signatures":[{"sig":"MEUCIARYTgKfOi3bsVWrE0Q61s5AQZ0MZBK5+/h8cjWpt87HAiEAlCNT5Ip+5k/ZgBRRt0xXt5/1iz9SWcNGMyoGaPD0Mb0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1482620},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"bdc59e22a0d511f16ad7648b97523313f4f03e09","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.3.2_1779271384696_0.9711788421354097","host":"s3://npm-registry-packages-npm-production"}},"9.4.0":{"name":"ship-safe","version":"9.4.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.4.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"e051fbed92fd2ba2feff828611c02533010b906e","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.4.0.tgz","fileCount":116,"integrity":"sha512-NSwQhdrpDZpuf+mQ461d48dLMznUNFTbhMsZ8oUnovx1gRLRIPWquu/zkzfTIOj3jYbpIpiGvmQ2EFIdoil0NA==","signatures":[{"sig":"MEUCIQCIOh2W5y/zEfS/yKW6WCJF0XOgNxNVBXkuj3gsxQdFygIgXKw1zniKGWHjF6T32ahx5KDxv8XiIrEP8thlqBnvZ1A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1502471},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"833a58c116e10759487f5265286a409347cf3d17","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 24 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.4.0_1783981904947_0.24566825035442452","host":"s3://npm-registry-packages-npm-production"}},"9.4.1":{"name":"ship-safe","version":"9.4.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.4.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"61b2ce725d6e7f90a6606a7712c6016455d09ca7","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.4.1.tgz","fileCount":116,"integrity":"sha512-dw0jElCjV+w1h8EG+rICAIyO9typLYHH/OW8xZIVXnL6s/10ZVnGj2suHeD35c4gj/6davqAytNQS2z7OKVtyA==","signatures":[{"sig":"MEQCIAgI0JicFJ3oVFtuxeaWMoqrt0H+/kJNnTuUsaDVqYViAiBXluM5IAszEK4myf6Lu9crxJOLLD9EYaoPM1bUzF874A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1503173},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"8cf8e40fa3218b96dc23b76dce69e6bf9b531b50","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 24 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.4.1_1783982865055_0.9894157010600326","host":"s3://npm-registry-packages-npm-production"}},"9.5.0":{"name":"ship-safe","version":"9.5.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.5.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"e991bbda8d132c32461fbb42a90bd3a3545a7ad0","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.5.0.tgz","fileCount":123,"integrity":"sha512-hjouSu4eKPVD8jRVx92faPjfn6uiEMPDZxYHUC6siFtYvhqTgs14eTo+sUF/lhhnTtyt+9HjtIF0AvamANsSLw==","signatures":[{"sig":"MEUCIQCtm6sZMiVRj7P54O7lERAU0y6nMRUn2oNDbs2odDx0kgIgXlAVaoi8TdNqKubqVzRugAWZ+CAgvcl5M7rAcpmVdTI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1557813},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"55a21ec4d13b8f0fe94e0ce4fe09ce13a655a08e","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.5.0_1784144886525_0.9023547180133453","host":"s3://npm-registry-packages-npm-production"}},"9.5.1":{"name":"ship-safe","version":"9.5.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.5.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"66c39117fcea2e6f327adf375aea67450a43a8cd","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.5.1.tgz","fileCount":124,"integrity":"sha512-r5cimz9Y4yQjnOuYjuX1QfCQFxbH38ooW5U8RTN1HWHOVzd3LxLQKgcAJV3IW/xecfWoVeYuJz4yb5XhwHGfLQ==","signatures":[{"sig":"MEQCIGSuOrSlVPezY2DyQttVEkG6OfxrvFrpJGPNERcHyGASAiBwPcq/aFTqILg6qy41MQVtCFDDBih19Yug1sttK7vZXA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1575131},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"ce5a331f44b546efab053d0a98f457c2cdd80cd1","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.5.1_1784145404259_0.8993531139996309","host":"s3://npm-registry-packages-npm-production"}},"9.5.2":{"name":"ship-safe","version":"9.5.2","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.5.2","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"e8abf441591de28ae617abaa8a8895289bc9ab6a","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.5.2.tgz","fileCount":124,"integrity":"sha512-WAPCfwCgHd2EmMDqHblfXpfjaVFyxoc719UK01iOsovqEx5KVsXZOI31B1qruxPASOhbvGhzu+yFYQDuUM/1IA==","signatures":[{"sig":"MEUCICpG351fKpB/fzFWU7UTRi5Crpl+hk4cL0PXUEq9GCSyAiEAhJM8u5pw+W13PYA1jpTBoPX8uxo8oJxsXNbFhi3kT7M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.5.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1586640},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b3764a85e665d5e71b61a5842cd1e9559c06139b","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.5.2_1784234883574_0.18363387441734802","host":"s3://npm-registry-packages-npm-production"}},"9.6.0":{"name":"ship-safe","version":"9.6.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.6.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"119c0b685542d162ea1846a21a7868d1315fdc5b","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.6.0.tgz","fileCount":125,"integrity":"sha512-+16xOGIPyHf4Tjb2ePTMl+rFpbjnom7sAFw2LvJ7dsDTIrFVFW2Y7UVz0E7bf0qljnIyGYiLsVVh9M3Lz+Ammg==","signatures":[{"sig":"MEYCIQDeGRKy/0u+A0P8f6jlFNGUcp2pvrd8YuZ4H8waLkoSbAIhAPIzJpqD/996VX9rcpOyvsrQ5sVISRjxVGtM9l93fNlt","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1605920},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"fbad79cfb66a93b9472291c28ed8bc472a3baa6a","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.6.0_1785083978360_0.4471721298500193","host":"s3://npm-registry-packages-npm-production"}},"9.6.1":{"name":"ship-safe","version":"9.6.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.6.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://github.com/asamassekou10/ship-safe#readme","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"177a7218a20870d52f1971f528691b5ff0d203fd","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.6.1.tgz","fileCount":125,"integrity":"sha512-J6NKZwU/lUDfmLNSxgnSgq2kyaTxSNO8m+IzOBIMVok9RDH1zEB44cvsEQxyJPw3a9SCH5HFr/vLMrLB7mXCRA==","signatures":[{"sig":"MEUCIQDY1IhIBoMMP2a2I/qsyA7Dg5zaMuPMutJhfAp7UwjN1gIgfjAbGAPcvNnyiuENjhyaRQt7VDyXLaPOHpSZlzaHo2w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.6.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1608385},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"cd9e304e21b6b1df9e51020c31a25cc5e9f7dcb3","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.6.1_1785561478797_0.3481828199283623","host":"s3://npm-registry-packages-npm-production"}},"9.6.2":{"name":"ship-safe","version":"9.6.2","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.6.2","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"62f9cae5c54c977752150e37f65f3e2fbbf5214f","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.6.2.tgz","fileCount":125,"integrity":"sha512-M0wwOO3chJ3NWHM42KIYFdZFhSpNjikG3m7kriFlYb2ShC8lq+2/zcvWKHk/KnwhFAeuNMeuwQXjUriavWaLEg==","signatures":[{"sig":"MEQCIEmUHrPyHR+Ny4lw4bk7aRZGLjM/o4TXmyo8SHsu7J6oAiB26qjaS8DzP3ceUlah/0xXrOARsdha52mJ92ty9cAHrA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.6.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1614663},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"fd8391547b4bd90a17d100a3ee687744aedd24dc","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.6.2_1785650096510_0.26173263092064714","host":"s3://npm-registry-packages-npm-production"}},"9.6.3":{"name":"ship-safe","version":"9.6.3","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.6.3","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"03eae2b2e1aa18450741b8e2cb28c9fe72334e22","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.6.3.tgz","fileCount":125,"integrity":"sha512-kTlVdrYAsFwWYyS9e5sw2I34Q3N4xCBPERb61ejbAoKapx7WDi40zYlAizeSrD7sMCCUyNYoB5hSYOHzwvR3vA==","signatures":[{"sig":"MEYCIQDFhh7KcCGt/qX78ypQ2+OYOmhlSDb6VG9qzdfkU6O2FQIhALIKNJeCAvhfj5HWvHvTGSvzFxW4V7oWldSWHjC5neuu","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.6.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1642326},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"ca57e5cc8c5908f46269396286adb3afa1ba351e","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.6.3_1785745177785_0.6110245108555721","host":"s3://npm-registry-packages-npm-production"}},"9.7.0":{"name":"ship-safe","version":"9.7.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.7.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"757e13222dc1fec2d7df6fe513992eae3a5837a4","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.7.0.tgz","fileCount":125,"integrity":"sha512-22XGpjiQttlVxmiTj5j87zv5t0M3bvilgAy0MljzQG1mpPIzWcLpG2/1rUQ7zxNYNrAqYcjxIhjAPK0aKqi+9w==","signatures":[{"sig":"MEUCIDGFDgGUpknYyoBKb4fV+55UXicsZWze6NdHC2O30WhBAiEAsr8FHS/4py7O3G4+DtxSI2k3shhkA1jVwkb92dWIFfw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1682111},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"288c79265115a45f8d8bd0a008595734b34add96","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.7.0_1785901930940_0.7011534116607641","host":"s3://npm-registry-packages-npm-production"}},"9.7.1":{"name":"ship-safe","version":"9.7.1","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.7.1","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"694c35d20df981e1e2d17ceccefb0ebb1de46ae8","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.7.1.tgz","fileCount":125,"integrity":"sha512-5SiJjyouLJbOw/OMf7eJIzGAQ9oqqy2RAg+PpU8PpdpReNwuqMWaYgbpxPc6JBDT6kJ78et79DWN5IQ+7cTaRw==","signatures":[{"sig":"MEQCIFxBQka2rsNIDJOPFgI3byzUktd0wJQgpkyGPLqEoOnNAiAtBlf4j+/3tD9QstDPGQluTpoBqYDQxX9gej+2poYxIQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1695350},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"31eec5e46ede8cc68f8e92fa59c364781a6fcc26","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.7.1_1786158972097_0.6335189696555534","host":"s3://npm-registry-packages-npm-production"}},"9.7.3":{"name":"ship-safe","version":"9.7.3","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.7.3","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"8d0f102be352071ca475c097e5222015f1219276","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.7.3.tgz","fileCount":127,"integrity":"sha512-Rvgta1cZ1NK1K08cRBjO+hPwTw1MF/F/IhTe2U63GM7/uEUYzCAKm8MYMyKm6lB0q9vxqrtgaIYgRsmqR59Ktg==","signatures":[{"sig":"MEQCIGifWObISXrBDmWiPq0ubzCY4Kepgba1dYy4vxWokvTnAiAYp3dinv78DBXNCGK9RYSoHeB/xWuID/SX8DFfIFo9rw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.7.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1704899},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"5c1e15709a2af2c10fb872668f253149967dbe0d","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.7.3_1786256806143_0.04541228966236255","host":"s3://npm-registry-packages-npm-production"}},"9.7.4":{"name":"ship-safe","version":"9.7.4","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.7.4","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"34f6ef8428db96ef5bd50424e569ef1e61e8d023","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.7.4.tgz","fileCount":128,"integrity":"sha512-VdTEMNGDDa0n8zq5HlpRL7tV45/LycWtxsv6B6ANfRt4OiOB0gTZXIV/ElyJ0pTT5iwhgGwrP5LRN8GFR5GwjQ==","signatures":[{"sig":"MEYCIQCKhsC00wcBuiSPVUpIY2OonlQS3s6CY8dd8RTCaPfPsQIhAKIlBj50NhjFHrLq23FmEiqW6RYb6COGi7ngyX9PT9NU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.7.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1708273},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"9c7e11867c7738db536f296833833f17027fff04","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.7.4_1786449265844_0.5435137051757655","host":"s3://npm-registry-packages-npm-production"}},"9.7.5":{"name":"ship-safe","version":"9.7.5","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.7.5","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"45df5d5e6d459a0f9ce9f9163eec8915cfadfb61","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.7.5.tgz","fileCount":130,"integrity":"sha512-JnjGfVhd6u+pzX6Xgbo9J+Sp3EtDQQLxYXJ5L4ZGDddLpxguzbUg84qSZOvAm4Hj1+OK9KwTOEMscpnJ20Y7HQ==","signatures":[{"sig":"MEQCID+Cb+tJdfRIteVxdpEma6rSzUCrVufb7TCaEtMqGCZkAiByzsyP+4ZA4Vp2bAwlR0mUdmN6RfZ8cQcA3B852KU8lA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.7.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1741715},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"2bc9fe37295e08d601eb87673e000b494de8d90a","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.7.5_1787126934465_0.2449500219700822","host":"s3://npm-registry-packages-npm-production"}},"9.7.6":{"name":"ship-safe","version":"9.7.6","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.7.6","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"8409ce4234be69f54e9508fe356266d914b6491a","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.7.6.tgz","fileCount":130,"integrity":"sha512-EFME49TCd04p3HPaOnzRDwpO2scZOlBRXRg56nbOFY/vRuOUo4RQgdqmFzNEHM0lCtQA3a9UXQYgBCnAzKGAwA==","signatures":[{"sig":"MEUCIQCvPpbFLmV9pVN82QabhI+0lnxahIdoFlpOlszheQNn+QIgbaWV2JKWV9LxePYJBO9z6unp/7CqfTpmtvzSEY8RXik=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCICTEP0KgsZZC7MtIWWZq63QoElXBfqC7u7pgzDgARF9zAiEA/csevuZe506I9ro1h+btQbXdE2X9ZpV30770C0AnA5Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.7.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1790984},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"b78ac4c3d639307a8ca58de5a44d8472d88814f6","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:corpus":"node benchmarks/run.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.7.6_1787904598888_0.3074232653344049","host":"s3://npm-registry-packages-npm-production"}},"9.8.0":{"name":"ship-safe","version":"9.8.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.8.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"20392cb8e376095d88dde2383cd63dab1079a2b0","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.8.0.tgz","fileCount":143,"integrity":"sha512-F/7D1TA3a00T8WLPcQ3Oy35bp1raHZVXUQ0DxCgvncEwVduhTsq3KQUiDjssG568MnvNA7Kt8WCoAaIPG8xL4g==","signatures":[{"sig":"MEUCIBxn4t0wGXWsKnW88nXMmjhXPzgHZS+N2HAF1yXu5sI1AiEA5h+TdiLJ2EffmhLA+WwrCIUrU/utHfb5LT9+zjHhbPc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQD1LyQWlYdLyHZ2/v+5CAV0tFhn+LGok7lY92Y6PITcTgIhAM3xOE6qhGYEMG249fAlJ962/MeK2WGomRtDFoiAQvsG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1995975},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"d2033dd4569b815c54441221ae6cead18ae389eb","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:fp":"node benchmarks/false-positives/run.mjs","benchmark:corpus":"node benchmarks/run.mjs","benchmark:fp:write":"node benchmarks/false-positives/run.mjs --write","benchmark:verdicts":"node benchmarks/verdicts.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write","benchmark:verdicts:write":"node benchmarks/verdicts.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.8.0_1788256890636_0.4454336243084873","host":"s3://npm-registry-packages-npm-production"}},"9.9.0":{"name":"ship-safe","version":"9.9.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@9.9.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"d5d812c3100cff5607d75d17763455c256a3b9e5","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-9.9.0.tgz","fileCount":144,"integrity":"sha512-MK66r9UF1LY04goifJ826z86TPyA9yX/ea7eOlOpbCQYTQB6gScENE6+jmAyWYnMTcKj5IEkh+KCWffngzCOhg==","signatures":[{"sig":"MEUCIH0LaYlk3WdP75eqfyZsabedmPMa+R4uJiqwTEOsUDhNAiEA4rnvcdqfz0sCjobrBtxhdi6d9itkzUqU2t4Q602hA2g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDADwnqjZ7JOAfLL9C9fR6rnE3eeHryacujofEoVJbLqQIgNVTfhkYQOm+kyMCXKWE4EnERn2JfQ//GUWbLVR8hb60=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@9.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2018208},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"a8c8cf3f25137e3d9a0166dda8e20da3109a1076","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:fp":"node benchmarks/false-positives/run.mjs","benchmark:apps":"node benchmarks/applications/run.mjs","benchmark:corpus":"node benchmarks/run.mjs","benchmark:fp:write":"node benchmarks/false-positives/run.mjs --write","benchmark:verdicts":"node benchmarks/verdicts.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write","benchmark:verdicts:write":"node benchmarks/verdicts.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_9.9.0_1788262264805_0.4910830313924812","host":"s3://npm-registry-packages-npm-production"}},"10.0.0":{"name":"ship-safe","version":"10.0.0","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli"],"author":{"name":"ship-safe contributors"},"license":"MIT","_id":"ship-safe@10.0.0","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"homepage":"https://shipsafe.sh","bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"bin":{"ship-safe":"cli/bin/ship-safe.js"},"dist":{"shasum":"94a9fdf5cc321b45f7a9c6b7772ccd4895977ff6","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-10.0.0.tgz","fileCount":146,"integrity":"sha512-GgQUSv0toEphdslmduK8BSuGYfXMAVMrO9iwGfaICpjqSDi0sXyk44u9rZlbZFJlsLnD1+5xqskDx4LIFPQ+7Q==","signatures":[{"sig":"MEUCIChBt2Cg+s9JxcT6pjhL1Qq0QhzDol4bChcjqBCjhdr3AiEA499I6vEzPjaC7QggIatCl2MAcBvCo9rci7gc4/2Cexs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCSgTOS6s1opJ3rF3COzcKXxQzYZnHEDYSikinERau7qgIgQ8EWCzRTHQVa57SQKdOnIDWtGPjCY05XD2DDQx1zMis=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@10.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2082481},"main":"cli/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"473dc5aaad3de76836312cded0f8f8a601858497","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:fp":"node benchmarks/false-positives/run.mjs","benchmark:apps":"node benchmarks/applications/run.mjs","benchmark:corpus":"node benchmarks/run.mjs","benchmark:fp:write":"node benchmarks/false-positives/run.mjs --write","benchmark:verdicts":"node benchmarks/verdicts.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write","benchmark:hermes-release":"node benchmarks/hermes-release-evidence/run.mjs","benchmark:verdicts:write":"node benchmarks/verdicts.mjs --write"},"_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"AI-powered multi-agent security platform. 29 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployment scanning (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"tmp":"tmp/ship-safe_10.0.0_1788608407193_0.15800045497997983","host":"s3://npm-registry-packages-npm-production"}},"10.1.0":{"_id":"ship-safe@10.1.0","bin":{"ship-safe":"cli/bin/ship-safe.js"},"bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"dist":{"shasum":"cf272a467852f204d0186a952be57cee91177dd1","tarball":"https://registry.npmjs.org/ship-safe/-/ship-safe-10.1.0.tgz","fileCount":151,"integrity":"sha512-F/7O95izbWcMxxClozRrYjgnuGiFDyxqDqBjTV8lQNzxJV/Y64t+k4uYTidIMj/yws4cy4PwEG3AxOFxoonjVA==","signatures":[{"sig":"MEUCIQCdJTVzUWrtrG8KMEkppocbgxxXVrz6bpr2CV73xr4hPgIgTUiGv3P3daoKWLU+43dKPK1ifqDXRbNk/CaB8h+knrU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICX3X1myizfByaa7vxH6nXfxPJ162MeTLxgWTipp4SS6AiB4u+XgeQOMS2KxTCndpslu3MDyVoeEqMejJVlSzMFIaQ=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/ship-safe@10.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2152447},"main":"cli/index.js","name":"ship-safe","type":"module","author":{"name":"ship-safe contributors"},"engines":{"node":">=18.0.0"},"gitHead":"723bb799917ea1137671da74bba408efac600dd1","license":"MIT","scripts":{"lint":"eslint cli/","test":"node --test cli/__tests__/*.test.js","lint:fix":"eslint cli/ --fix","ship-safe":"node cli/bin/ship-safe.js","ci:pending":"gh api \"repos/asamassekou10/ship-safe/actions/runs?status=action_required&per_page=50\" --jq '.workflow_runs[] | \"\\(.created_at[0:16])  \\(.name)  [\\(.head_branch)]  run=\\(.id)  approve: gh api --method POST repos/asamassekou10/ship-safe/actions/runs/\\(.id)/approve\"'","benchmark:fp":"node benchmarks/false-positives/run.mjs","benchmark:apps":"node benchmarks/applications/run.mjs","benchmark:corpus":"node benchmarks/run.mjs","benchmark:fp:write":"node benchmarks/false-positives/run.mjs --write","benchmark:verdicts":"node benchmarks/verdicts.mjs","benchmark:corpus:write":"node benchmarks/run.mjs --write","benchmark:hermes-release":"node benchmarks/hermes-release-evidence/run.mjs","benchmark:verdicts:write":"node benchmarks/verdicts.mjs --write"},"version":"10.1.0","_npmUser":{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"},"homepage":"https://shipsafe.sh","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli","mcp","sarif","agent-security","ai-agents","hermes","static-analysis"],"overrides":{"brace-expansion":"^5.0.8"},"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"_npmVersion":"10.8.2","description":"The independent security agent for AI-written software. A deterministic engine finds issues across application code, AI agents, MCP servers, skills, dependencies, CI/CD, and secrets. An investigation layer traces whether each one is real and reports the e","directories":{},"maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"_nodeVersion":"20.20.2","dependencies":{"ora":"^8.0.1","chalk":"^5.3.0","commander":"^12.1.0","fast-glob":"^3.3.3","write-file-atomic":"^7.0.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.3.0","globals":"^17.6.0","@eslint/js":"^10.0.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ship-safe_10.1.0_1789973808330_0.6169433838853908"}}},"time":{"created":"2026-02-03T07:55:52.650Z","modified":"2026-09-21T06:56:48.808Z","1.0.0":"2026-02-03T07:55:52.808Z","1.0.1":"2026-02-03T08:13:20.989Z","2.0.0":"2026-02-04T18:11:28.451Z","3.0.0":"2026-02-17T22:15:51.859Z","3.1.0":"2026-02-18T04:59:07.366Z","3.2.0":"2026-02-19T10:08:14.838Z","4.0.0":"2026-02-27T07:19:34.829Z","4.1.0":"2026-02-27T17:46:25.580Z","4.2.0":"2026-03-05T05:44:03.915Z","4.3.0":"2026-03-08T18:28:13.623Z","5.0.0":"2026-03-17T04:54:29.010Z","5.0.1":"2026-03-17T06:45:44.904Z","6.0.0":"2026-03-23T04:01:34.534Z","6.1.0":"2026-03-24T01:46:53.684Z","6.1.1":"2026-03-27T02:22:45.209Z","6.2.0":"2026-04-01T18:53:48.181Z","6.3.0":"2026-04-01T20:42:26.611Z","6.4.0":"2026-04-02T04:31:23.897Z","7.0.0":"2026-04-07T00:30:15.530Z","8.0.0":"2026-04-11T14:20:53.039Z","9.0.0":"2026-04-15T14:14:11.015Z","9.1.0":"2026-04-20T22:26:02.809Z","9.1.1":"2026-04-20T22:29:34.120Z","9.1.2":"2026-04-25T02:37:52.123Z","9.2.0":"2026-04-26T16:41:57.187Z","9.2.1":"2026-04-27T04:13:03.331Z","9.2.2":"2026-04-29T04:18:31.520Z","9.2.3":"2026-05-04T06:46:01.522Z","9.2.4":"2026-05-04T23:15:56.573Z","9.3.0":"2026-05-12T06:10:55.896Z","9.3.1":"2026-05-20T09:31:09.964Z","9.3.2":"2026-05-20T10:03:04.904Z","9.4.0":"2026-07-13T22:31:45.138Z","9.4.1":"2026-07-13T22:47:45.287Z","9.5.0":"2026-07-15T19:48:06.721Z","9.5.1":"2026-07-15T19:56:44.449Z","9.5.2":"2026-07-16T20:48:03.770Z","9.6.0":"2026-07-26T16:39:38.506Z","9.6.1":"2026-08-01T05:17:58.993Z","9.6.2":"2026-08-02T05:54:56.663Z","9.6.3":"2026-08-03T08:19:37.948Z","9.7.0":"2026-08-05T03:52:11.129Z","9.7.1":"2026-08-08T03:16:12.239Z","9.7.3":"2026-08-09T06:26:46.367Z","9.7.4":"2026-08-11T11:54:26.042Z","9.7.5":"2026-08-19T08:08:54.622Z","9.7.6":"2026-08-28T08:09:58.983Z","9.8.0":"2026-09-01T10:01:30.744Z","9.9.0":"2026-09-01T11:31:04.953Z","10.0.0":"2026-09-05T11:40:07.324Z","10.1.0":"2026-09-21T06:56:48.478Z"},"bugs":{"url":"https://github.com/asamassekou10/ship-safe/issues"},"author":{"name":"ship-safe contributors"},"license":"MIT","homepage":"https://shipsafe.sh","keywords":["security","secrets","scanner","sast","devsecops","red-team","penetration-testing","vulnerability-scanner","sbom","owasp","sql-injection","xss","ssrf","supply-chain","llm-security","prompt-injection","api-security","docker-security","kubernetes","cicd-security","mobile-security","jwt","cors","cli","mcp","sarif","agent-security","ai-agents","hermes","static-analysis"],"repository":{"url":"git+https://github.com/asamassekou10/ship-safe.git","type":"git"},"description":"The independent security agent for AI-written software. A deterministic engine finds issues across application code, AI agents, MCP servers, skills, dependencies, CI/CD, and secrets. An investigation layer traces whether each one is real and reports the e","maintainers":[{"name":"asamassekou","email":"alhassane.samassekou@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\".github/assets/ship-safe-logo-2026.png\" alt=\"Ship Safe Logo\" width=\"180\" />\n</p>\n<p align=\"center\"><strong>The independent security agent for AI-written software. It finds issues, investigates whether they are real, and shows you the evidence.</strong></p>\n<p align=\"center\"><a href=\"https://shipsafe.sh\">Website</a> · <a href=\"https://shipsafe.sh/docs\">Docs</a> · <a href=\"https://shipsafe.sh/security\">Security & Data Flow</a> · <a href=\"https://shipsafe.sh/benchmarks\">Benchmark</a> · <a href=\"https://shipsafe.sh/pricing\">Pricing</a> · <a href=\"https://shipsafe.sh/blog\">Blog</a> · <a href=\"https://github.com/asamassekou10/ship-safe/contribute\">Contribute</a></p>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/ship-safe\"><img src=\"https://badge.fury.io/js/ship-safe.svg\" alt=\"npm version\" /></a>\n  <a href=\"https://www.npmjs.com/package/ship-safe\"><img src=\"https://img.shields.io/npm/dm/ship-safe.svg\" alt=\"npm downloads\" /></a>\n  <a href=\"https://github.com/asamassekou10/ship-safe/actions/workflows/ci.yml\"><img src=\"https://github.com/asamassekou10/ship-safe/actions/workflows/ci.yml/badge.svg\" alt=\"CI\" /></a>\n  <a href=\"https://opensource.org/licenses/MIT\"><img src=\"https://img.shields.io/badge/License-MIT-yellow.svg\" alt=\"License: MIT\" /></a>\n  <a href=\"https://github.com/asamassekou10/ship-safe/stargazers\"><img src=\"https://img.shields.io/github/stars/asamassekou10/ship-safe?style=social\" alt=\"GitHub stars\" /></a>\n  <a href=\"https://github.com/sponsors/asamassekou10\"><img src=\"https://img.shields.io/badge/Sponsor-%E2%9D%A4-ea4aaa?logo=github\" alt=\"Sponsor\" /></a>\n</p>\n\n## Ship Safe CLI\n\nShip Safe runs locally in your repo and works in two layers.\n\nA **deterministic engine** finds issues across application code, AI agents, MCP configs, prompts, dependencies, CI/CD, secrets, and cloud-adjacent configuration. Fast, repeatable, and benchmarked — this is the sensor layer.\n\nAn **investigation layer** then decides what the findings are worth. It traces the value that reaches a sink, searches the project for controls a rule says are missing, builds attack chains across configuration no single file contains, and — when you ask it to — probes a leaked key against its provider. Every conclusion carries the pass that reached it and the lines it read:\n\n```\nCONFIRMED — traced end to end (10)\n\n    NoSQL Injection via $where [high]\n    app/data/allocations-dao.js:78  NOSQL_INJECTION_WHERE\n    why: threshold is assigned from the HTTP request and reaches the sink without validation on that path.\n    decided by: dataflow\n      1. value reaches NOSQL_INJECTION_WHERE here  app/data/allocations-dao.js:78\n      2. getByUserIdAndThreshold is called here with threshold  app/routes/allocations.js:23\n      3. threshold is assigned here  app/routes/allocations.js:20\n    fix: Replace $where with standard MongoDB operators ($eq, $gt, $regex, etc.)\n```\n\n<sub>Real output from <code>ship-safe investigate</code> against OWASP NodeGoat. The tainted value is destructured in a route file and passed into a DAO three directories away.</sub>\n\nStart with one command:\n\n```bash\nnpx ship-safe\n```\n\nNo signup. No API key required for scanning. Works offline for core checks. AI-backed red-team modes use your configured provider when available.\n\nUse `--no-ai` to guarantee a fully local scan. Provider-backed classification, deep analysis, and GPT-Red send bounded context directly to your selected provider after best-effort credential masking. See [Security & Data Flow](https://shipsafe.sh/security) for exact boundaries and context limits.\n\n<p align=\"center\">\n  <img src=\".github/assets/demo-repl.gif\" alt=\"Ship Safe REPL demo\" width=\"800\" />\n</p>\n\n---\n\n## Quick Start\n\n```bash\n# Interactive REPL: scan, fix, and ask questions in one session\nnpx ship-safe\n\n# Full audit: secrets + 30 agents + deps + remediation plan\nnpx ship-safe audit .\n\n# Investigate: confirmed / likely / unresolved / refuted, with the evidence\nnpx ship-safe investigate .\nnpx ship-safe investigate . --all       # also detail unresolved and refuted\nnpx ship-safe investigate . --verify    # probe leaked keys against their providers\n\n# Before you open an unfamiliar folder with an agent: what runs on open?\nnpx ship-safe trust ~/Downloads/take-home\nnpx ship-safe trust . --json\n\n# What can an AI agent working in this repo actually reach?\nnpx ship-safe capabilities .\n\n# AI agent red-team scenarios for agent-readable content\nnpx ship-safe red-team . --gpt-red\n\n# Interactive fix agent: plan, diff, approve, verify the path closed\nnpx ship-safe agent .\nnpx ship-safe agent . --severity critical   # critical findings only\nnpx ship-safe agent . --branch --pr         # fix on a branch + open a PR\n\n# Undo the last fix\nnpx ship-safe undo\n\n# CI/CD mode — fails on any critical finding\nnpx ship-safe ci . --sarif results.sarif\nnpx ship-safe ci . --fail-on high              # stricter: critical or high\n\n# Gate on evidence instead of severity: block only what was established\nnpx ship-safe ci . --fail-on-verdict confirmed\nnpx ship-safe ci . --ignore-refuted            # do not block on what was argued away\n```\n\nFor pull requests, compare a trusted base scan with the head scan so existing\nrepository debt remains visible without blocking unrelated changes:\n\n```bash\n# On the trusted base revision\nnpx ship-safe ci . --fail-on none --no-deps \\\n  --write-baseline-report /tmp/ship-safe-base.json\n\n# On the pull request head\nnpx ship-safe ci . --base-report /tmp/ship-safe-base.json --fail-on high\n```\n\nThe base artifact contains hashed finding identities, relative paths, and rule\nmetadata. It does not store raw matched secrets. PR results classify findings\nas introduced, resolved, unchanged, or uncertain; ambiguous matches are shown\nbut do not block the pull request.\n\n## What Ship Safe Finds\n\n| Area | Examples |\n|------|----------|\n| AI and LLM security | Prompt injection, agent hijacking, excessive agency, memory poisoning, RAG poisoning, unsafe tool calls |\n| MCP and agent configs | Over-broad tool permissions, poisoned registries, untrusted transports, dangerous allowlists |\n| Application security | SQL/NoSQL injection, XSS, SSRF, auth bypass, path traversal, insecure API routes |\n| Secrets and compliance | API keys, tokens, credentials, PII, leaked secrets in git history |\n| Supply chain | Typosquatting, dependency confusion, risky install scripts, unpinned AI actions |\n| CI/CD | Pipeline poisoning, unpinned GitHub Actions, secret logging, unsafe workflow triggers |\n\n## How It Works\n\n1. **Scan locally** - Ship Safe inspects your repo with targeted agents and skips checks that do not apply.\n2. **Investigate each finding** - Separate passes decide whether it is real, ranked so a cheaper one never overturns a more expensive one: a traced data path outranks a model's reading of the same file, and a probe that authenticated outranks both.\n3. **Read the evidence** - Findings resolve to confirmed, likely, unresolved, or refuted, each citing the lines it was concluded from, so you can disagree with a step instead of a severity label.\n4. **Fix with control** - The agent proposes a plan and diff, asks before writing, verifies the result, and keeps changes reversible.\n5. **Gate in CI** - Use `ship-safe ci` to fail risky builds and upload SARIF into GitHub code scanning.\n\n<p align=\"center\">\n  <img src=\".github/assets/demo-agent.gif\" alt=\"Ship Safe agent demo\" width=\"800\" />\n</p>\n\n---\n\n## \"Why not just ask my coding agent to review the repo?\"\n\nYou can, and you should. It will find real things. But there are three questions it structurally cannot answer about its own work.\n\n**Did the agent that wrote this code just mark its own homework?** Asking the author whether the author made a mistake is not a review. Ship Safe is a separate reviewer with a separate method, and it disagrees with itself in public — a data-flow trace overturns the heuristic pass, and a live probe overturns both.\n\n**Can it see what it can reach?** A coding agent reviewing your repo cannot read your MCP server config, cannot enumerate the permissions it was launched with, and is the actor whose reach is in question. `ship-safe capabilities` reads all of it from outside and reports the combinations that are dangerous together while unremarkable apart:\n\n```\n  CRITICAL  Repository-controlled instructions reach an unattended write capability\n    1. CLAUDE.md is read as instructions and can be changed by anyone who lands a commit\n       CLAUDE.md:1\n    2. Claude Code runs without per-action approval\n       .claude/settings.json:2\n    3. shell execute granted: Bash(git push:*)\n       .claude/settings.json:3\n    4. filesystem write granted: Write\n       .claude/settings.json:3\n    5. mcp-tool write granted: mcp__github__create_pull_request\n       .claude/settings.json:3\n    Impact: Text committed to this repository can direct the agent to write files\n            or run commands with no human in the loop.\n    Boundary: Require approval for write and execute tools during sessions on\n              untrusted branches, or remove the pre-granted entries.\n```\n\nEach of those lines is unremarkable on its own. Together they are a path from a pull request to a privileged write, and no single-file review can see it, because no single file contains it.\n\n**Is it consistent, and can you prove it got better?** Ask twice, get two answers. Ship Safe's engine is deterministic, and its conclusions are gated in CI by a benchmark that scores *conclusion quality*, not pattern coverage: how many known-real findings it settles, how much known noise it refutes, and whether it ever refutes something real. That last number's budget is zero — it is the only error class that loses a vulnerability silently. See [benchmarks/](./benchmarks/).\n\n## Why Developers Use It\n\n- **Built for AI-native apps**: catches risks in agents, MCP servers, prompts, RAG flows, managed-agent configs, and AI-powered CI.\n- **Works with AI clients**: expose Ship Safe to Codex, Claude Desktop, Cursor, Windsurf, and other MCP clients through the local stdio server.\n- **Fast local feedback**: run it before a PR, during review, or inside CI without sending code to a hosted scanner.\n- **Fixes are reviewable**: every suggested change is shown as a diff before it touches your files.\n- **Works with your stack**: JavaScript, TypeScript, Python, config files, infrastructure files, GitHub Actions, and more.\n- **Open source core**: MIT-licensed CLI with docs, examples, and a growing agent system.\n\n## Free CLI, Paid Team Workflows\n\nThe open-source CLI is the fastest way to scan any repo locally. Upgrade when you need a hosted workflow around the same scanner:\n\n| Need | Use |\n|------|-----|\n| Local scans, audits, and agent-assisted fixes | Free CLI |\n| Scan history, cloud dashboard, and PDF reports | Pro |\n| Shared workspace, PR Guardian, team reports, and collaboration | Team |\n\nCompare plans at [shipsafe.sh/pricing](https://shipsafe.sh/pricing).\n\nShip Safe Cloud, the hosted dashboard for scan history, PR Guardian, billing, and team workflows, is developed in a private repository because it contains commercial product code and hosted infrastructure workflows. The public `ship-safe` repo remains focused on the MIT-licensed CLI, security agents, rules, fixtures, CI integrations, and documentation. See [Ship Safe Cloud](./docs/cloud.md) for the repo boundary.\n\n---\n\n## Security Agents\n\nAll agents run in parallel. Each skips irrelevant projects automatically.\n\n| Agent | Category | What It Detects |\n|-------|----------|-----------------|\n| **InjectionTester** | Code Vulns | SQL/NoSQL injection, command injection, XSS, path traversal, XXE, ReDoS, prototype pollution |\n| **AuthBypassAgent** | Auth | JWT flaws (alg:none, weak secrets), CSRF, OAuth misconfig, BOLA/IDOR, TLS bypass |\n| **SSRFProber** | SSRF | User input in fetch/axios, cloud metadata endpoints, internal IPs |\n| **SupplyChainAudit** | Supply Chain | Typosquatting, wildcard versions, suspicious install scripts, dependency confusion |\n| **ConfigAuditor** | Config | Docker (root user, :latest), Terraform, Kubernetes, CORS, CSP, Firebase, Nginx |\n| **SupabaseRLSAgent** | Auth | service_role key in client code, tables without RLS, anon key inserts |\n| **LLMRedTeam** | AI/LLM | OWASP LLM Top 10: prompt injection, excessive agency, system prompt leakage |\n| **MCPSecurityAgent** | AI/LLM | MCP server misuse, tool poisoning, typosquatting, unvalidated inputs |\n| **AgenticSecurityAgent** | AI/LLM | OWASP Agentic AI Top 10: agent hijacking, privilege escalation, Kimi K3/OpenAI-compatible tool-call misuse |\n| **RAGSecurityAgent** | AI/LLM | Context injection, document poisoning, vector DB access control |\n| **MemoryPoisoningAgent** | AI/LLM | Instruction injection in agent memory files, hidden Unicode payloads (ASI-01, ASI-05) |\n| **PIIComplianceAgent** | Compliance | SSNs, credit cards, emails, phone numbers in source code |\n| **VibeCodingAgent** | Code Vulns | AI-generated code anti-patterns: no validation, empty catches, TODO-auth |\n| **ExceptionHandlerAgent** | Code Vulns | Empty catches, unhandled rejections, leaked stack traces (OWASP A10:2025) |\n| **AgentConfigScanner** | AI/LLM | Prompt injection in .cursorrules, CLAUDE.md, malicious Claude Code hooks |\n| **MobileScanner** | Mobile | OWASP Mobile Top 10 2024: insecure storage, WebView injection, debug mode |\n| **GitHistoryScanner** | Secrets | Leaked secrets in git commit history |\n| **CICDScanner** | CI/CD | Pipeline poisoning, unpinned actions, secret logging (OWASP CI/CD Top 10) |\n| **APIFuzzer** | API | Routes without auth, mass assignment, GraphQL introspection, debug endpoints |\n| **ManagedAgentScanner** | AI/LLM | Claude Managed Agent misconfigs: always_allow policies, unrestricted networking (ASI-03–ASI-07) |\n| **HermesSecurityAgent** | AI/LLM | Tool registry poisoning, function-call injection, skill permission drift (ASI-01–ASI-10) |\n| **AgentAttestationAgent** | Supply Chain | Unpinned agent versions, missing integrity hashes, unsigned manifests (ASI-10, SLSA L0) |\n| **AgenticSupplyChainAgent** | Supply Chain | Over-privileged AI CI actions, OAuth scope creep, unsigned AI webhook receivers (ASI-02, ASI-06) |\n| **RobloxSecurityAgent** | Supply Chain | Malicious Roblox/Luau Toolbox assets (runtime asset injection, `rbxassetid://` loaders, `HttpEnabled`, payloads hidden in instance attributes) |\n| **ModelScanAgent** | Supply Chain | Code-execution payloads in ML model weights (pickle opcodes in `.pt`/`.pkl`/`.ckpt`), `torch.load` without `weights_only`, scanner-evasion archives (CWE-502, CWE-506) |\n| **TrustBoundaryAgent** | Agentic | GhostApproval symlink attacks (config-named links into `~/.ssh`/`~/.aws`/`.env`), repo symlinks escaping the tree, and Friendly Fire run-on-review instructions in agent-read docs (CWE-59, CWE-61) |\n| **SlopSquatAgent** | Supply Chain | Hallucinated / phantom package imports (slopsquatting) — bare imports not declared, installed, or builtin, plus known AI-hallucinated names (CWE-1357) |\n| **ClickFixAgent** | Supply Chain | ClickFix / fake-CAPTCHA paste-and-run lures (fake error + Win+R/Ctrl+V/command-bar keystrokes, PowerShell cradles) and fake-installer npm lifecycle scripts (CWE-1357, CWE-506) |\n| **InstallGuardAgent** | Supply Chain | npm worm behaviors in lifecycle scripts (credential harvesting, env exfiltration, destructive `rm -rf`, obfuscated `node -e`) and weaponized `binding.gyp` node-gyp actions (CWE-506, CWE-829) |\n\n**Investigation passes**, in the order their evidence outranks each other:\n\n| Pass | Rank | What it establishes |\n|------|------|---------------------|\n| **VerifierAgent** | heuristic | Pattern check around the finding. Never states more than \"likely\" |\n| **DeepAnalyzer** | analysis | LLM taint reading of the finding and its file, with the citation validated |\n| **DataflowInvestigator** | dataflow | Traces the value back to its origin, across one function boundary and into other files. JavaScript, TypeScript, and Python |\n| **AbsenceInvestigator** | presence | Searches the project, or the handler, for the control a rule says is missing |\n| **LiteralContextInvestigator** | presence | Decides findings about a written-in value by what surrounds it — prose, a help string, or a reserved address |\n| **CapabilityGraph** | chain | Builds attack chains from configuration no single file contains |\n| **RedosReproducer** | reproduction | Runs a flagged pattern against generated input in a worker with a deadline |\n| **SecretsVerifier** | reproduction | Presents a leaked key to its provider. Opt-in: this discloses the key |\n\nA claim whose cited file or line does not resolve is recorded but never decides a verdict. Two passes of equal rank that disagree resolve to unresolved rather than to whichever verdict is scarier.\n\n**Also:** ScoringEngine\n\n---\n\n## The REPL\n\n```\n$ ship-safe\n\n  ███████╗██╗  ██╗██╗██████╗     ███████╗ █████╗ ███████╗███████╗\n  ...\n\n  v9.4.1  ·  DeepSeek  ·  ~/my-project\n\n  /scan to find issues  ·  /agent to fix them  ·  /help for more\n\nshipsafe ›\n```\n\n| Command | What it does |\n|---------|-------------|\n| `/scan` | Re-scan the project |\n| `/agent` | Run the interactive fix loop |\n| `/findings` | List findings from the last scan |\n| `/show <n>` | Full detail on finding n |\n| `/plan <n>` | Preview fix plan for finding n (no writes) |\n| `/undo [--all]` | Revert the last fix (or all fixes) |\n| `/share` | Publish scan report as a public URL (7 days) |\n| `/diff` | Show git working-tree diff |\n| `/provider <name>` | Switch LLM provider mid-session |\n| `/quit` | Exit (also `Ctrl-D` or `Ctrl-C`) |\n\nAnything not starting with `/` is sent to the LLM as a free-form question, with your latest scan results as context.\n\n---\n\n## CI/CD\n\n```yaml\n# .github/workflows/security.yml\nname: Security Audit\non: [push, pull_request]\njobs:\n  security:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - name: Security gate\n        run: npx ship-safe ci . --sarif results.sarif\n      - uses: github/codeql-action/upload-sarif@v3\n        if: always()\n        with:\n          sarif_file: results.sarif\n```\n\nA GitLab CI version is in [docs/examples/gitlab-security-workflow.yml](docs/examples/gitlab-security-workflow.yml).\n\n### GitHub Action with inline PR findings\n\nUse the Action from a `pull_request` workflow when you want critical and high\nfindings attached to the changed lines. Keep `pull_request_target` out of this\npath for forked contributions: Ship Safe refuses that privileged combination\nbecause the checkout may contain untrusted code.\n\n```yaml\nname: Ship Safe\non:\n  pull_request:\n\npermissions:\n  contents: read\n  pull-requests: write\n  security-events: write\n\njobs:\n  scan:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: asamassekou10/ship-safe@v9.9.0\n        with:\n          fail-on: high\n          inline: true\n```\n\nInline comments are opt-in and only post critical/high findings. Re-running\nthe job updates the summary without creating duplicate inline comments.\n\n---\n\n## LLM Support\n\nWorks with any provider — auto-detected from environment variables. Use `--provider <name>` to override.\n\nAnthropic · OpenAI · Google · DeepSeek · Kimi K3 / Moonshot · Groq · Together · Mistral · xAI · Perplexity · Ollama · LM Studio · any OpenAI-compatible endpoint\n\nKimi defaults to `kimi-k3` through `MOONSHOT_API_KEY` or `KIMI_API_KEY`. Use `--provider kimi --model kimi-k3` for long-context GPT-Red and deep-analysis runs.\n\nFor Kimi K3-specific long-context red teaming:\n\n```bash\nnpx ship-safe red-team . --gpt-red --provider kimi --model kimi-k3 --k3-long-context\n```\n\nShip Safe also checks Kimi K3 / OpenAI-compatible tool-call implementations for dynamic tool loading from prompt context, missing tool allowlists, forced tool calls on untrusted input, and replayed tool results without the original assistant tool-call message.\n\nNo API key required for core scanning. AI classification and `red-team --gpt-red` use your configured provider when available, with deterministic offline fallback for GPT-Red checks.\n\n---\n\n## Suppress False Positives\n\n```python\npassword = get_password()  # ship-safe-ignore\n```\n\n`critical` findings are always reported. An inline comment cannot hide one, and\nan attempt to suppress one is recorded in the scan. The comment is meant for a\nhuman ruling out a false positive, and anything that can write a line of your\nsource — including an AI agent — can write the comment too, so the highest\nseverities do not honor it. Every suppression is counted, so a scan that\nsilenced findings never reads like one that had none.\n\nOrdinary code rules do not grade Markdown prose or fenced code examples as\ndeployed source. Secrets are still scanned everywhere, and agent-readable\nfiles such as `AGENTS.md` and `CLAUDE.md` keep their dedicated prompt-injection\nand trust-boundary checks. To review fenced examples intentionally, use\n`--include-doc-examples` with `scan`, `audit`, or `ci`.\n\n```gitignore\n# .ship-safeignore\ntests/fixtures/\ndocs/\n```\n\n### How noisy is it?\n\nRecall is the easy half of a scanner. A tool that flags everything catches\neverything and is useless, so we measure the other half: what Ship Safe says\nabout code that is almost certainly fine.\n\n| project | findings | critical | grade |\n|---|---|---|---|\n| [express](https://github.com/expressjs/express) | 26 | 0 | C |\n| [requests](https://github.com/psf/requests) | 15 | 1 | C |\n| [flask](https://github.com/pallets/flask) | 28 | 0 | D |\n| [chalk](https://github.com/chalk/chalk) | 4 | 0 | B |\n\nDown from 1031 findings across the same four projects before v9.6.3, verified\nagainst NodeGoat and DVWA so the drop is reduced noise rather than lost\ndetection. The 1 remaining critical is a false positive and the benchmark says\nwhich and why.\n\nCorpus pinned by commit, reproducible with one command, limits documented:\n**[benchmarks/false-positives/](benchmarks/false-positives/)**\n\n### How does it compare to Semgrep, Gitleaks, Trivy, CodeQL?\n\nRun Ship Safe alongside them, not instead of them. CodeQL does interprocedural\ntaint analysis Ship Safe does not attempt, Gitleaks is the specialist for\nsecrets, and Trivy has a real CVE database behind it.\n\nShip Safe covers a narrower question: what an AI coding agent just did to your\nrepository, your CI, and your local tool configuration. MCP client config,\nagent memory poisoning, hallucinated-package imports and AIBOM are the areas\nwhere we found no equivalent public rules in the other four.\n\nFull coverage matrix, verified against their public registries, including where\nthey beat us: **[docs/comparison.md](docs/comparison.md)**\n\n---\n\n## Add a Badge\n\n```markdown\n[![Ship Safe](https://img.shields.io/badge/Ship_Safe-A+-22c55e)](https://shipsafe.sh)\n```\n\n---\n\n## What's Next\n\n**10.1 is a precision release.** It keeps the verified Hermes Agent 10.0\nbaseline and tightens attestation so Ship Safe's own advisory citations are not\nmistaken for unsigned agent resources. Existing plugin and adapter checks are\npartial; terminal posture, ACP/TUI, current cron lifecycle, and credential\nreachability remain explicit work rather than implied coverage. See the\n[coverage matrix](docs/hermes-coverage-matrix.md).\n\nSee the [roadmap](./ROADMAP.md) for what is planned and what is deliberately\nnot. Focused contributions and benchmark-backed fixes are welcome.\n\n## Contributing\n\nShip Safe is open source, and the best contributions are small, focused improvements that make AI-assisted development safer.\n\nGood first areas:\n\n- Add a focused security agent for an AI, MCP, CI, cloud, or supply-chain risk\n- Add a precise security rule to an existing agent\n- Add vulnerable fixtures and regression tests\n- Write examples for local scans, CI gates, red-team workflows, and MCP/agent setup\n\nStart here:\n\n- [Good first issues](https://github.com/asamassekou10/ship-safe/contribute)\n- [Contributor guide](./CONTRIBUTING.md)\n- [Add an agent](./docs/adding-an-agent.md)\n- [Add a security rule](./docs/adding-a-security-rule.md)\n- [Write a custom agent plugin](./docs/custom-agent-plugins.md)\n- [Handle MCP environment variables safely](./docs/mcp-env-safety.md)\n- [Use Ship Safe with Codex](./docs/integrations/codex.md)\n- [Use Ship Safe with Claude Code](./docs/integrations/claude-code.md)\n- [Release process](./docs/releasing.md)\n\n---\n\n## Sponsors\n\nShip Safe is MIT-licensed and free forever.\n\n<p align=\"center\">\n  <a href=\"https://github.com/sponsors/asamassekou10\">\n    <img src=\"https://img.shields.io/badge/Sponsor%20Ship%20Safe-%E2%9D%A4-ea4aaa?style=for-the-badge&logo=github\" alt=\"Sponsor Ship Safe\" />\n  </a>\n</p>\n\n---\n\n## Star History\n\n[![Star History Chart](https://star-history.dera.page/svg?repos=asamassekou10/ship-safe&type=Date)](https://star-history.dera.page/#asamassekou10/ship-safe&type=date)\n\n---\n**Ship fast. Ship safe.** — [shipsafe.sh](https://shipsafe.sh)\n","readmeFilename":"README.md"}