Shipshape / MCP

Repository intelligence, without the guesswork

Know what to fix next.

Shipshape turns public GitHub evidence into a small, ranked maintenance queue. It reads; it never pushes, edits, clones, or executes a repository.

shipshape-mcp.aranlucas.workers.dev/mcp

Prefer a browser? Open the settings dashboard to check repository settings against your own rules.

01 / READ ONLY

Safe by construction

One narrow GitHub OAuth scope, public repositories only, and a client with no mutation method.

02 / REPRODUCIBLE

Rules, not vibes

Stable checks and fixed weights make every score explainable and every recommendation traceable.

03 / HONEST

Unknown stays unknown

Permission- and plan-gated evidence never quietly becomes a passing security signal.

portfolio_snapshot

Find recently active public repositories that most need attention.

repo_readiness

Audit publication, branch, delivery, and security signals together.

branch_risk

Inspect the protections around a branch before follow-up work begins.

delivery_hygiene

Summarize recent commits, pull requests, and workflow health.

security_posture

Normalize code, dependency, and secret-scanning evidence.

standards_audit

Check packages against a shared engineering baseline with commit-pinned evidence.

settings_drift

Compare repository settings with declarative rules and get reviewable fix commands.

action_plan

Turn failed and unknown checks into a bounded maintenance queue.