Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add asamassekou10/ship-safe --skill ship-safe-fixgit clone --depth 1 https://github.com/asamassekou10/ship-safeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/asamassekou10/ship-safe/ship-safe-fix)<a href="https://agentmods.dev/skills/asamassekou10/ship-safe/ship-safe-fix"><img src="https://agentmods.dev/badge/skills/asamassekou10/ship-safe/ship-safe-fix/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/asamassekou10/ship-safe/ship-safe-fix"><img src="https://agentmods.dev/badge/skills/asamassekou10/ship-safe/ship-safe-fix.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 7 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Anti-Refusal · line 27 Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.Fix: Remove jailbreak framing that nullifies safety policies or restrictions. Skill content must not instruct the agent to ignore its guidelines or operate without guardrails.
- medium MCP Rug Pull · line 16 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 22 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 42 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 48 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 57 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 69 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00047 | $0.00719 |
| Opus 5 | $0.00023 | $0.00360 |
| Sonnet 5 | $0.00009 | $0.00144 |
| Haiku 4.5 | $0.00005 | $0.00072 |
Grade A, and why
ship-safe-fix scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Ship Safe — Auto-Fix Security Issues
You are using Ship Safe's remediation engine to automatically fix security issues in this project.
Step 1: Preview the fixes
Always start with a dry run to show what will change:
npx ship-safe@latest remediate $ARGUMENTS --dry-run 2>&1
If $ARGUMENTS is empty, default to . --all (fix both secrets and agent findings):
npx ship-safe@latest remediate . --all --dry-run 2>&1
Flags:
- No
--allflag → only fixes hardcoded secrets (moves to env vars) - With
--all→ also fixes: TLS bypass (rejectUnauthorized: false), Docker:latesttags, debug mode enabled,dangerouslySetInnerHTMLwithout sanitization,shell: truein exec/spawn
Step 2: Present the preview
Show the user what will be changed:
- List each file that will be modified
- Show the before/after for each change
- Group by fix type (secrets, TLS, Docker, debug, XSS, shell)
- Note any files that will be created (
.env.example,.env)
Step 3: Apply fixes (with confirmation)
Ask the user if they want to proceed. If yes:
npx ship-safe@latest remediate . --all --yes 2>&1
If the user only wants to fix secrets (not agent findings):
npx ship-safe@latest remediate . --yes 2>&1
Step 4: Post-fix verification
After applying fixes:
-
Run a quick scan to verify secrets were removed:
npx ship-safe@latest scan . --json 2>/dev/null -
Report the results — how many issues were fixed vs. remaining
-
For remaining issues that couldn't be auto-fixed, offer to fix them manually by reading the code and applying targeted changes
Step 5: Follow-up actions
Suggest:
- Review
.env.example— make sure variable names make sense - Add
.envto.gitignoreif not already there - Rotate exposed secrets — run
npx ship-safe rotate .for step-by-step guides - Update baseline — run
/ship-safe-baseline .to update after fixes - Stage changes — offer to stage the modified files with git
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 80 lines · 47 tokens per session scan A 7fda1a1d6b49
ship-safe-fix is a skill published in the GitHub repository asamassekou10/ship-safe (842 stars, last pushed 5d ago), licensed MIT. It adds 47 tokens to every session and 719 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
security-review
Security audit focused on OWASP Top 10 — injection, auth flaws, secrets exposure, IDOR, and more. Use when reviewing code for vulnerabilities, before deploying to production, or auditing a new codebase.
security-audit
Audit code and infrastructure for security vulnerabilities. Use when performing security reviews, checking for OWASP Top 10 issues, auditing dependencies, or hardening applications.
depsguard
Install and run DepsGuard, a zero-dependency CLI that scans and fixes package manager configs (npm, pnpm, yarn, bun, uv) for supply chain security best practices.
optimize-cc-md
Interactively helps users optimize their CLAUDE.md files. Use when user asks to "optimize my CLAUDE.md", "my CLAUDE.md is too long", "improve organization", or "split my CLAUDE.md". Runs validation, explains issues conversationally, and helps create @import files to reduce size and improve structure.
skillpm
Manage npm-distributed Agent Skill packages with skillpm.
validate-cc-md
Validates CLAUDE.md files for size, imports, and structure. Use when user asks to "check my CLAUDE.md", "why is my CLAUDE.md too long", "validate imports", or "fix CLAUDE.md errors". Checks file size limits (30KB warning, 50KB error), @import directives, frontmatter in .claude/rules/, and section organization.