Observed arrival · 2026-09-03
ClearToShip checks the leaks AI coding tools leave behind
A local and CI security scanner for AI-built apps, checking code, database policies, dependencies, and exposed credentials before deployment.
Field notes
The CLI reads a repository locally or in a CI runner and reports findings across four surfaces: TypeScript server code, SQL migrations, package registries, and secrets. Its database checks replay migrations into a final schema model, while dependency checks consult npm, PyPI, and OSV.dev; the page also describes 36 first-party rules and 234 entropy-gated credential patterns. Anonymous version lookups can reportedly be disabled with --offline.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue