CLI package
Published npm scanner for JavaScript and TypeScript repos. It checks env boundaries, Stripe webhook safety, Supabase/Firebase evidence, debug routes, paid API usage controls, CI, docs, lockfiles, and release hygiene.
npm packagePublic proof of work
These are real public assets: npm packages, GitHub Actions, MCP registry publishing, demo repos, and bounty-ready launch workflows. They show the kind of scoped work Tate Programs can repeat for founders and teams.
Core wedge
Published npm scanner for JavaScript and TypeScript repos. It checks env boundaries, Stripe webhook safety, Supabase/Firebase evidence, debug routes, paid API usage controls, CI, docs, lockfiles, and release hygiene.
npm packageMarketplace action wrapper that can fail CI or upload SARIF into GitHub code scanning, so Shipcheck findings show up where developers already review security alerts.
Marketplace listingMCP server for authorized local repo scans that returns text, Markdown, JSON, or SARIF output through standard MCP clients.
MCP npm packageExample reports
Shipcheck reports a debug API route, missing Supabase RLS proof, and missing paid API usage controls in a fixture app designed to mirror common launch mistakes.
View demo repoThe site includes a fixed-scope MCP review offer and sample report for package metadata, registry readiness, install config, and tool-safety notes.
Read sample reportA same-day report format for auth, public data, client-side secrets, deploy config, database rules, and payment boundaries.
Read sample reportBounty and growth systems
Torque project that rewards builders for completing secure-launch events: scanning, verifying fixes, sharing reports, and referring other builders.
Repo Demo postDashboard for spotting Solana ecosystem narratives and product opportunities from public activity sources.
Repo Live appReusable resume, platform answers, audit offer, follow-up notes, and operating plan so outreach stays consistent and honest.
See workStatic site with paid offers, sample reports, payment links, self-checkers, and proof links for launch work.
Open homeCommercial path