# ShipSafe — Independent security verification (slim) > ShipSafe — Independent security verification, an MCP server by ship-safe.co, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data… - Full: https://www.anchorterminal.com/tools/ship-safe-scanner.md (~500 tokens) · this version ~430 tokens · JSON https://www.anchorterminal.com/tools/ship-safe-scanner.json · canonical https://www.anchorterminal.com/tools/ship-safe-scanner - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 # ShipSafe — Independent security verification > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by ship-safe.co (https://ship-safe.co) - Category: Secrets & credential vaults (https://www.anchorterminal.com/categories/secrets.md) - Listed because: It's published in the registry under ship-safe.co, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access. ## Facts - MCP registry: `co.ship-safe/scanner` 0.6.4 - Endpoint: https://ship-safe.co/api/mcp (streamable HTTP) - Package: npm `@ship-safe/mcp` (stdio) - Website: https://ship-safe.co - npm downloads a week: 877 - Registry entry updated: 2026-09-28 ## Tools - Tools: the endpoint asks for credentials before listing them (checked 2026-10-04 22:21 UTC) - JSON: https://www.anchorterminal.com/api/v1/tools/ship-safe-scanner.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming