
Shippable
io.github.Egarterv0.11.6Updated Oct 6, 2026
Find leaks in AI-built apps: open Supabase/Firebase data, exposed keys, unsafe edge functions
Overview
AI-generated overview
Scans AI-built apps for exposed Supabase or Firebase data, leaked keys, and unsafe edge functions.
- What it does
- Shippable is a local MCP server that inspects an app's configuration and backend setup to surface security problems. According to its registry description, it looks for open Supabase or Firebase data, exposed keys, and unsafe edge functions. No tool list is published, so the exact commands and output format are not documented here.
- When to use it
- Worth considering when you have built or inherited an app that uses Supabase or Firebase and you want an assistant to check it for exposed data, leaked credentials, or risky edge functions before shipping. Less relevant for projects that do not use those backends.
- Requirements
- Runs as a local process over stdio, installed from the npm package shippable-dev, so Node.js and npm are needed. The manifest declares no authentication, environment variables, or headers, and it is desktop-only with no web executable.
Before you install
The server inspects app configuration and backend settings, which may include credentials or keys; treat any findings as sensitive. No tool list is published, so confirm what it reads and whether it changes anything before running it against a real project. The registry description mentions exposed keys, so avoid pasting live secrets into shared logs or chats.
Installation
In SourceWeft
- Open Shippable in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Tools
0Tool metadata has not been indexed yet.
Version history
1- v0.11.6LatestOct 6, 2026


