▮ AgenticCLI — local-first business critical tooling for the agentic era
Your agent already shipped it. Did it just re-break it?
Long agentic loops quietly regress the app that makes you money. ShipGuard is the deterministic, local security and config check that runs inside the loop — same diff, same verdict, a real exit code your agent can read, every time.
Runs alongside every agent and terminal.
Claude Code, Codex, Cursor — or any CLI, hook or CI. It reads exit codes natively, so your agent acts on the result.
The most important gate for your agent.
live
ShipGuard
The release gate for AI-built apps. Five deterministic checks for the mistakes Claude Code, Codex and Cursor actually make — run locally, in about two seconds, before anything ships.
- secrets
- auth
- payments
- database
- deployment
The security harness
Agents ship code faster than any human review can keep up. ShipGuard wraps the agent loop in a deterministic security check — so the mistakes it checks for are caught before they ship.
without a harness
with ShipGuard
Critical checks that matter for your business.
The places AI agents actually break production — tuned to the mistakes Claude Code, Codex and Cursor make most. Framework-aware regex and string matching, not one generic rule for every stack.
Secrets
Hardcoded API keys, tokens and credentials — before they reach your git history.
Auth
Unprotected admin routes, missing guards and broken session checks.
Payments
Unverified webhooks and missing signature checks on Stripe & friends.
Database
SQL injection, unsafe queries and destructive or exposed migrations.
Deployment
Debug flags, source maps and dev config shipped to production.
ShipGuard guards your deployments, branches & PRs as agents help you ship faster.
What makes a security gate work for agents — and why each property is load-bearing.
agent-native
JSON + exit codes. That's the API.
Your agent scans, reads the JSON recommendation field, applies each fix, and re-scans until it comes back clean. No dashboard, no alert queue — the entire interface is stdout and structured JSON.
deterministic
Not an LLM. A rule engine.
Same code → same score → same exit code. Every time, on every machine. An LLM gives three different answers to the same question — ShipGuard gives one, and your agent can trust it enough to branch on it without asking a human.
local-first
Code never leaves the machine.
Free scans need no account and run on your machine. Pro scans connect once to download rule bundles via an authenticated edge gateway, then scan locally. Either way, no code, file paths, or file contents are ever transmitted. Rules come down. Code never goes up. A small pseudonymous usage ping (version, verdict, duration, CI flag) is sent unless you opt out with SHIPGUARD_TELEMETRY=0 or DO_NOT_TRACK=1 or shipguard telemetry disable.
framework-aware
Framework-aware rules, not one generic pattern.
ShipGuard's rules are tuned to Next.js App Router routes, Supabase RLS migrations, Stripe webhook handlers, and Firebase security rules — regex and string matching that knows route.ts in app/api/ is a public endpoint, not just a file with a string in it.
one command
Install and scan in seconds.
No config files. No account. No setup wizard. One npx command and ShipGuard scans your project — locally, privately, in seconds.
/loop
The observe step in every agent loop.
Every coding agent runs a loop: reason → act → observe → repeat. ShipGuard is the observe step — the deterministic checkpoint between "the agent wrote code" and "the code ships." It returns structured findings the agent can reason about and act on in the next iteration, closing the loop without a human in the middle.
hooks
A hard gate, not a polite request.
A CLAUDE.md instruction is a hope. A hook is a guarantee. Wire ShipGuard as a PreToolUse hook or a pre-push git hook and it fires deterministically at the boundary between "agent wants to push" and "code leaves your machine." Exit 1 blocks (with --strict). The agent doesn't get a vote.
/goal
The stop condition agents actually trust.
Goal-based loops need an objective stop condition — not "does this look safe?" but a binary yes/no the agent can check deterministically. Passed with --strict, ShipGuard's exit code is that condition: exit 0 means no blocking findings remain. The agent's goal becomes: "get to exit 0." It can iterate autonomously — scan, fix, re-scan — with a clear, machine-verifiable definition of done.
ShipGuard Pro
The free check catches the obvious. Pro is the maintained corpus, kept current as new patterns emerge — plus, on the roadmap, the audit trail that flags what your agent quietly re-broke.
free — catches the common, high-severity mistakes agents make most: hardcoded secrets, unverified webhooks, unguarded routes
pro — catches the complex workflows, framework-specific patterns & more
always-current
live threat-intel corpus
Cloud-delivered rule bundles — updated continuously without a CLI upgrade. Pro rules are updated in the cloud as new patterns are added; the free corpus updates on a slower cadence by design.
deep stack coverage
web · database · auth · secrets · supply chain
Rules that understand your tech stack — web frameworks, database ORMs and migrations, authentication providers, secret patterns, and supply chain dependencies. Pro goes deeper than the free modules into stack-specific failure modes that basic pattern matching can't reach.
shipguard.policy.yml
custom policy files
Define which findings block, which warn, and which paths to ignore — per project. Your policy travels with your repo and your agent respects it automatically.
Start free.
No credit card. No account required for the free tier. Simple pricing — the local gates stay free forever.
$0 forever
Unlimited local scans on every push — for every solo builder and agent.
- Unlimited local scans
- 5 cloud scans / mo
- All 5 check categories
- Deterministic exit codes
- --strict CI gate
- --json for CI & agents
- Community support
$19 /mo
month-to-month · no annual option
For the solo builder who wants the full rule corpus in the cloud, month-to-month.
- Everything in Free
- 10 cloud scans / mo
- Full corpus access
- Month-to-month
$29 /mo
The full gate — deep backend-as-a-service (Supabase, Firebase) checks and the always-current corpus, for shipping in earnest.
- Everything in Plus
- 100 cloud scans / mo
- Supabase RLS & Firebase deep checks
- Custom policy files
- Priority rule updates & email support
FAQ
Does my code ever leave my machine?
Which agents and tools does it work with?
Is it really free?
How is this different from a linter or Snyk?
What languages and frameworks are supported?
Can my agent run it automatically?
From the blog
AI agent security
Vetting an AI Agent Framework: We Probed 4 SDKs
AI agent security
AI Agent Security Risks: 7 Checks No Scanner Answers
AI supply chain security
AI Supply Chain Security: 0 Advisories, Then 46
Secrets & API key leaks
Detect Hardcoded Secrets: 6 Shapes, 4 Scanners
Secrets & API key leaks
GitLab Secret Detection: 1 Finding, Then 0, Then 2
MCP security
MCP Security Best Practices: What 4 Scanners Miss
All posts by topic → · Quick start: run ShipGuard locally → · ShipGuard vs Snyk vs Semgrep →