Ship Check
com.uxcontinuumv0.2.0Updated Oct 5, 2026
Scan a deployed app URL for exposed keys, open Supabase tables and missing security headers.
Overview
AI-generated overview
Scans a deployed app URL for exposed API keys, open Supabase tables, and missing security headers.
- What it does
- Ship Check is a remote MCP server that inspects a deployed web application by URL. According to its registry description, it looks for exposed keys, open Supabase tables, and missing security headers. No tool list is published, so the exact tool names and output format are not documented here.
- When to use it
- Useful when you want an assistant to run a quick security sanity check on a live deployment, for example after shipping a site or before sharing a URL publicly. It is aimed at catching common misconfigurations rather than full penetration testing.
- Requirements
- A remote endpoint at uxcontinuum.com over streamable HTTP; no packages, environment variables, or headers are declared. The manifest declares no authentication, so no account or API key is stated as needed. The target app must be reachable at a URL.
Before you install
The scan is performed by a third-party remote service, so the URL you submit is sent to that provider. Results may reveal exposed keys or open database tables; treat any findings as sensitive and rotate credentials rather than sharing them. No authentication is declared, so consider what a public endpoint implies for your data.
Installation
In SourceWeft
- Open Ship Check in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"ship-check": {
"type": "http",
"url": "https://uxcontinuum.com/api/mcp"
}
}
}Tools
0Tool metadata has not been indexed yet.
Version history
1- v0.2.0LatestOct 5, 2026


