Multi-layer security scans for AI-generated code and MCP servers. Detects leaked API keys, PII, prompt injection, and insecure configs.
Pro doesn't sell scans — it sells client-ready proof. PDF reports, Evidence Packs, verified badges.
AI-generated code ships fast — but security doesn't keep up. MCP servers introduce an entirely new class of vulnerabilities.
One layer misses. The next catches. Each vulnerability goes through 2–3 independent detection methods.
Known vulnerability signatures — regex patterns for API keys (AWS, Stripe, OpenAI…), PII formats, injection keywords, and MCP misconfigurations.
Mathematical verification — Shannon entropy analysis catches unknown key formats. Luhn algorithm validates card numbers. Checksum verifies national IDs.
Smart filtering — variable names, file paths, and surrounding code determine if a match is a real threat or a false positive (test data, examples, comments).
3 layers for secrets · 2 layers for PII · 2 layers for injection · 5 checks for MCP
Both run from your terminal. No signup, and neither command uploads the files it inspects.
Reads the eligible files under the path you give it, on your machine, and reports what it finds. It does not rewrite the files it scans — --fix prints remediation guidance instead of patching code.
A successful scan increments a monthly usage count in ~/.project-shield/. A badge or Evidence Pack file is written only when you pass --badge or --evidence. With no license key on the machine the scan makes no network call; if an already-stored Pro license cache has expired, the CLI contacts Polar to re-validate it.
A separate check for the AI-agent environment itself: 9 environment checks and 7 hook checks over your Claude Code settings files, CLAUDE.md, .env, and hook definitions.
Hook commands and configuration are read and pattern-matched — never executed. Free runs 3 audits a month and shows the full score with the free-tier environment findings; Pro runs 20 and adds the remaining environment findings, the hook findings, JSON output, and the audit Evidence Pack. The result is recorded in .claude/.shield/audit-state.json so a later run can flag configuration changes.
No false sense of security. If critical issues exist, your Scan Badge won't be issued until they're fixed. Fix-it guide included.
Every scan produces tamper-proof evidence. Clients can independently verify your security posture.
A Pro scan seals a badge UUID and a verify-URL field into the Evidence Pack. That UUID and the SHA-256 result hash are what you hand a client — this site does not host a badge lookup page today.
Scan results are sealed with SHA-256 hash. Any modification is instantly detectable.
Full scan metadata — timestamp, ruleset version, file count, findings summary — bundled in a verifiable package.
Expert-curated rules with SHA-256 verification. Tampered rulesets are rejected before scanning begins.
Scan → Evidence → Trust
Synthetic example. It was produced by the v2.0.0 Evidence Pack code with made-up findings — it is not a customer report,
not a certification, and not a live verification. Every file path, finding, and identifier in it is invented.
File SHA-256: a0e6db41b86cc13d08a35906c8ecf4c5e74c570ddb5db93bed6af1316d80353b
| AI (ChatGPT / Claude) | Project Shield | |
|---|---|---|
| MCP-specific rules | Generic advice | Research-based rules |
| Detection layers | Single pass | Multi-layer (2–3×) |
| Verifiable output | Chat response | Sealed Evidence Pack |
| False positive mgmt | None | shield-ignore + tuned thresholds |
| Client proof | Screenshot? | Verified Scan Badge + URL |
Add one step to your GitHub Actions. Shield fails the build if critical issues are found.
Shield exits with code 1 on critical findings — your CI pipeline stops automatically.
Two offers are live today: Free and Pro. No credit card required to scan.
Checkout is provided by Polar and currently displays Clouvel, the legacy publisher account for Project Shield. Applicable tax is calculated from your billing address and shown before payment.
After payment, Polar delivers your license key automatically. Activate it with npx project-shield activate PSH_…, then confirm with npx project-shield status. Activation registers the machine with Polar under a device label built from its hostname and OS user name; npx project-shield deactivate releases it.
Run your first scan in under a minute. No signup required.
Click to copy