Custom Software Development, AI Tooling
ShipDoctor
Audit your App Quality, Performance, and Security + Get the Prompts to Fix it.

We built ShipDoctor to help us audit incoming codebases. Now we let external users use ShipDoctor to assess their own app health. Upload a zip, connect a GitHub repo, and then run a scan. We produce a graded report on security, performance, accessibility, code quality, AI slop, unnecessary code, missed opportunities, and dependencies — with repair prompts for every finding.

The Result
A web product for self-serve repo audits, plus a feature-rich CLI used in Bowtie consulting engagements. One scan produces a deeply informed report that combines industry standards and our decade of experience to grade every aspect of your codebase. Then we output repair prompts, or take the reigns and handle the repairs for you.
Most codebases accumulate risk quietly: secrets in history, bloated dependencies, accessibility gaps, AI-generated noise, SEO and infrastructure opportunities nobody has time to chase. AI generated apps compound those issues. ShipDoctor looks at your code and provides a graded audit you can actually act on. It is the backbone of every one of our consulting intakes, and now available for public use.
ShipDoctor.co lets a user upload a zip or connect a GitHub repo (forked into an org that controls the scan). From there they run an audit and get a report with a grade and score on each category, every suggested issue and fix, and ready-to-use prompts to address each finding. It a deep scan, well beyond AI bug scanners and commons skills files.
We use it every day, and constantly update our mix of threats, rules, and best practices. For consulting work we use an even larger toolbox, and can adjust tuning for strictness, severity floors, and add modules specific to your codebase.
How the audit works
ShipDoctor combines static scanners, proprietary formulas and rules, and structured AI analysis passes across eight categories:
- Security — secrets, vulnerable deps, Semgrep rulesets, and AI/LLM-specific risks like prompt-injection surfaces and unsanitized model I/O
- Performance — bundle weight, image weight, and judgment passes for N+1 queries, waterfalls, and missing caching
- Accessibility — axe / jsx-a11y where the stack supports it, plus semantic and keyboard-flow review
- Code quality — complexity, duplication, test presence, and architecture smells
- AI slop — redundant comments, hallucinated APIs, copy-paste variants, and other AI-generated clutter
- Unnecessary code — dead exports, unused deps, commented-out blocks, unreachable branches
- Missed opportunities — CI, tests, SEO/meta tags, security headers, monitoring, upgrade paths
- Dependencies — outdated majors, license flags, abandoned packages, and recommended replacements
Every category and module can be switched on or off per audit. New modules and rules (evolving HIPAA standards, for example) plug in frequently.
Privacy is the default: org copies are ephemeral (TTL’d and auto-cleaned) and anonymized — repos are double anonymized and kept private at all times, with client identity only in a private registry. Code that cannot touch the org can still be audited via local zip or folder through the CLI.
Any stack, Made Better
Input repos can be JS/TS, Python, PHP/WordPress, Ruby, Go, Java, .NET, static sites, or mixed monorepos. ShipDoctor goes way beyond tools that just check your standing site.
Test coverage comes in tiers:
- Universal Tier runs on every repo — testing gitleaks, Semgrep, osv-scanner, jscpd, complexity and presence checks, plus all Claude passes. This alone produces a substantive audit.
- Ecosystem packs Stack specific tests are activated from your detected code. Stack detection is evidence-based (lockfiles, manifests, extension census, framework fingerprints, etc).
- Custom Overrides Our team can easily override and expand into client-specific solutions when we see fit - or when input when detection guesses wrong.
DIY or We Do It For You
We use ShipDoctor on every consulting engagement — run the audit, walk the report with you, estimate the work, and fix what matters. You can self-serve on ShipDoctor.co, or hand us the repo and we handle the full loop: scan, prioritize findings, scope a quote, and handle the repairs.
If you worry about technical debt, or unknown issues buried in your AI codebase (which you should), reach out to us.