For developers shipping with Claude, Cursor or Copilot · SHPBL · Shippable™
SHPBL audits your repository against a governed software capability library —then repairs, harvests and retainsthe capability worth using again.
We ship software. Then you ship software. Together, we shape the world.
Disposable generation versus reusable capability.
AI coding agents generate software.
SHPBL makes software capability reusable.
It audits your repository as it is, screens catalogued capabilities against your architecture, and harvests what it learned into a library you keep. You drive the method from your chatbot, the HTTP API, or the files themselves.
Free repository evaluation, with no key and no card. $39/mo runs the full gauntlet and keeps every run. $499 to own the library as files.
Own the Complete Master Library — $499 · one purchase, two shipments.
The six-step method
The SHPBL launch film · 2026
Presented by my AI Founder Twin · Written & approved by Kenneth E. Sweet Jr.
Start with your own code
Paste a public repository and get the real audit — inventory, spine, risk signals and the capabilities already inside it. Free, no key, nothing kept.

Reading what is already there
Most of a repository is not reusable capability. One block of it is.
It reads what is already in your repository and lifts out the parts that solved something real, with provenance. Everything else is left exactly where it sits.
Six facets, one crystal
Every colour on this site is one of the six lit facets of the mark, and each facet owns one concern of the run. Nothing is tinted for variety.
- 01 · harvestReading what is already thereIt reads what is already in your repository and lifts out the parts that solved something real, with provenance. Everything else is left exactly where it sits.See the plate ↓
- 02 · evaluateVerdict before repairEvery finding is tagged and located — defect, missing dependency, performance risk — and nothing is written until the verdict is on paper.See the plate ↓
- 03 · composeParts into wholesVerified parts are composed into higher-order capability instead of being rewritten from scratch, and composites are counted separately from candidates.
- 04 · libraryOn the shelf, not in a chat logEach kept capability lands on a shelf with a name, a citation and a licence, readable by the next agent that opens the repository. Chat logs are not a library.
- 05 · repairThe right part in the right placeApproved repairs fit verified components into the broken structure, then prove the result before anything is allowed to move.
- 06 · shipNothing moves unauthorisedWrite-back is authorised, single-use and expiring: a signed build intent or nothing moves, and what clears the gate arrives as a pull request you can read.
The same instrument, handed over three ways
There is one method here, and it does not change with what you pay or how you call it. Run it free from the chatbot you already use or from a script over the HTTP API, borrow it by the month and keep what it produces in your own repository, or buy the library outright as files and hold it forever. Nothing is a separate product with a separate philosophy — they are three ways to hold the same thing.
Delivery one · Free, from a chatbot or the API
Try it
Free
Diagnose any repository you have the right to read — a properly licensed public repo, your own, or a private repo you have access to — from your chatbot over MCP, or from a script over the HTTP API.
- The repository evaluation: full audit, ranked repair order and a sealed ledger of what was found
- Every capability your repository already holds, with signature, file, line and contract
- The same seventeen tools whichever way you call in: MCP server or HTTP API
- It stops at the composition boundary: neither library is searched, so no candidates, library rows or proposed architecture come back — and nothing is retained
No key, no card, no sign-up over MCP or the API.
Delivery two · $39 a month
Borrow the library
$39/mo
The full gauntlet: licensed execution through both library searches, composition, verification and a result kept in your own repository as a pull request.
- The library read to your agent as cited rows, so it composes against real prior art
- The full `run_gauntlet` conductor, from audit through verified delivery
- Write-back: the report, the diffs and the harvested capabilities land in your repo
- One key for both transports — use it from an agent, from CI, or from a script
- Your runs are yours outright. The library and the technique stay ours.
Cancel any time. Your runs stay yours.
Delivery three · $499 once
Keep the library
$499
Own the Complete Master Library as files, licensed in perpetuity — not a subscription.
- The catalogued capabilities, the seven strategy volumes and the evaluation system, as files
- A perpetual license to that release: no server call, no meter, no expiry
- One purchase, two shipments — a copy goes to a nonprofit you choose
A separate product. Ordered here, shipped to you.
Free and $39/mo are the same server, reached from the chatbot you already use or over the HTTP API. $499 is the library itself, ordered here and shipped to you as files.
Verify before you buy
The claims are open to inspection
Read six complete repository runs, verify the release checksums, or watch the governed discovery engine add accepted software to the public ledger. Negative verdicts and inconclusive tests stay visible.
For technical readersExplore the complete method, evidence and libraryOpen the full story: the problem, six-step method, live runner, reports, trust controls, the component library, licensing, the discovery machine and the stewardship program.Expand the full technical story
The problem · what a repository costs you today
You keep paying to rediscover your own software
Assisted development made this worse, not better: technical debt now arrives faster than anyone can read it. More code lands per week, less of it is understood by the person responsible for it, and none of the reasoning behind it is written down anywhere an agent can read next month.
The answer to all three is one document: the evaluation library — free to download, and the same procedure every paid run obeys.
Nobody knows what the repo already contains
The capability you need was written eighteen months ago by someone who left. So it gets written again, slightly differently, and now there are two.
The evaluation names every capability in the repo, with file, line and stated contract.
Generated code arrives with no paper trail
An assistant hands you a plausible implementation and no answer to where it came from, whether it is licensed, whether it was verified, or what it supersedes.
Every capability SHPBL applies carries source, parents, licence status and acceptance rule.
Every run starts from zero
The reasoning that fixed one repository evaporates when the chat closes, so the next repository pays for the same discovery all over again.
A licensed run harvests what it learned into a library you keep and reuse on the next repo.
Web runner · free · no card · account required
Audit a repository right here
Point it at any public GitHub repository up to medium size and it returns the same audit our paid lanes start from: inventory, language spread, spine files, risk signals from the tree alone, and every exported capability with its file, line and stated contract. Every line comes from the repository's own bytes. One free run per account every 72 hours; the report is cached and stays readable, and anything already audited here is free to read forever. A free run does not retain harvested capability in a personal reusable library — that is what a licensed lane adds.
Ceiling: 1,500 readable source files and 15 MB. Larger repositories are refused before anything is read — those run on the Practitioner lane or through your own chatbot over MCP.
Already audited — free to read, no run spent
Open any report in its own window, or load it back into the runner above.
- sindresorhus/p-limit@main5 caps · 11 files · 5 reads
- sindresorhus/p-map@main6 caps · 10 files · 1 reads
What we believe · and therefore what we sell
We ship software. Then you ship software.
SHPBL is one company doing one thing: reading software honestly, then handing you engineered capability you can actually own. Everything on this page — the free run, the monthly borrow, the library you keep — is that single act, delivered in a different form.
Software should be owned, not rented.
You buy files and a licence, not permission that expires. The release you purchase keeps working with no key to check in with, no meter, and no runtime of ours between you and your customers.
The method is the product.
Read the repository blind, say what is actually there, screen candidates against catalogued prior art, and refuse most of them. The library is the memory that method reasons over — 29 projects of engineered capability, kept and cited.
A run that says change nothing is a good run.
The instrument is built to reject. Most of the catalogue is wrong for any given repository, and saying so is the work. We publish the runs that ended in a hold alongside the ones that ended in a merge.
What your run produces is yours.
Your repairs and your harvested capabilities belong to you outright — no licence back to us, no contribution loop, no claim. The library and the technique stay ours. That line never moves.
The method, start to finish
Six steps, in this order, every time. Your agent — over MCP — or your script, over the HTTP API does the work in your repository; SHPBL never sits inside your production runtime. What changes between the free run and a paid one is how much of the library your agent may read, and whether the capability it harvests is retained and reusable.
One run, start to finish
- 1
Point at a repo
Tell the chatbot you already use to audit a GitHub repository — or POST the same tool from a script. Nothing to install.
All three deliveries
- 2
Read it blind
The repository is surveyed as it actually is before any suggestion is made — files, languages, spine files, risk signals.
All three deliveries
- 3
Audit
What exists, what works, what hurts, and what must be left exactly as it is.
All three deliveries
- 4
Repair and harvest
A ranked repair order with diffs and guards, plus the capabilities your repository already contains, named and classed into a sealed ledger.
All three deliveries
- 5
The composition boundary
A free run establishes that new capability could be composed here — then stops, before either library is searched. No candidates, no library rows, no architecture.
Free stops here
- 6
Compose, then keep it
Practitioner continues: both libraries searched, candidates evaluated, new capability composed and verified, then landed in your own repository as a pull request.
$39/mo, 7 free days
Nothing is written before the verdict, and nothing leaves the ring before the gate. A run that ends with “this already works” has still completed the circle.
A valid result is: don't touch this, it already works. That is not a failure mode — it is the philosophy holding. Watch a run happen step by step.
ASSISTANT SHPBL
───────── ─────
prompt ──▶ generate ──▶ paste repo ──▶ read ──▶ reject most
│ │
▼ ▼
[ it compiles ] [ named capability ]
│ │ where it came from
▼ ▼ licence, contract
chat closes write back + shelve
│ │
▼ ▼
░ nothing kept ░ ██ library, reusable ██
│ │
└──▶ next repo starts at 0 └──▶ next repo starts here- ░Disposable: the reasoning evaporates with the chat window.
- ██Reusable: the capability is named, cited and read by the next run.
- ▶One step of the method — never skipped, never reordered.
The jobs people hire this for
When I inherit a repository I did not write, I want an honest inventory of what is in it, with files and lines, so I can plan work without guessing what already exists.
When I am about to build a capability, I want to know whether this repository — or prior art — already solved it, so I do not ship a second, slightly different copy of it.
When I accept generated code, I want provenance, licence status and an acceptance rule attached to it, so I can defend it in review six months from now.
When I finish a run that taught me something, I want that reasoning kept as a reusable capability, not a chat log, so the next repository starts ahead of the last one.
Who this is not for
Four groups should close this tab now, and we would rather say so than waste your afternoon.
- Teams that need a SOC 2 report before procurement — we hold no SOC 2 or ISO certification, and will not pretend a date for one.
- Developers who want an AI to write the code for them. SHPBL rejects most candidates on purpose; generation is a different tool, and you should keep it.
- Anyone who wants a managed dashboard to log into. This is a method you drive from your chatbot, your CI, or files you own.
- Repositories nobody is allowed to change. If the answer must be "touch nothing", a free run will tell you that and you will have spent nothing.
Leading a team with procurement questions? Read the answers written for team leads.
Three ways to reach it
The method is the product; the transport is your choice. Speak to it as an MCP server from your chatbot, call it as an HTTP API from a script, or run it offline as files. In TypeScript there is a fourth door onto the same tools — the typed @shpbl/sdk client, which reads the tier of every tool before it spends a call.
Transport one
MCP server
Connect the chatbot you already use — Claude, ChatGPT, Cursor, Copilot — and ask it to audit a repository in plain words.
shpbl.com/mcp · OAuth sign-in, or a static key for clients that cannot sign in
Transport two
HTTP API
The same seventeen tools over plain HTTP, so CI, a script or a service can run the method with no agent in the loop.
POST /api/public/v1/tools/{tool} · JSON in, JSON out, same key
Transport three
The library as files
Take the method offline: the procedure, the catalogue and the compiler as files you run by hand, with nothing calling home.
Free evaluation library, or the Complete Master Library at $499
Plainly: what this is
The instrument
A method that reads your repository and tells the truth about it
It surveys the code blind, names what exists, what works, what hurts and what must not be touched, then hands back a ranked repair order and the capabilities your repository already contains.
The memory
A governed library of reusable software it can reason against
The library keeps 1,000+ engineered components separate from 3,000+ runnable capability units your agent composes from, plus composites recorded apart. It includes software for tamper-evident audit trails, forensic replay, blast-radius limits, spend control, drift monitoring and evidence capsules. Each entry states its verification status and claim ceiling. The material comes from 29 originating projects; no model runs inside the SHPBL runtime and the library is not model output.
The terms
Free to run. $39 a month to keep and reuse what it finds. $499 to own the library.
No seat count, no runtime permission service, no expiry on the release you bought. Your runs are yours outright; the library and the technique stay ours.

Verdict before repair
It labels the defect before it offers you a fix.
Every finding is tagged and located — defect, missing dependency, performance risk — and nothing is written until the verdict is on paper.
What a run hands back
One document, sealed by SHA-256: the verdict, the findings with file and line, the ranked repair order, every capability candidate that was screened and why most were rejected, the combinations the run designed for that repository, and where anything it proposes to apply came from. Below is a real one — the run an independent reviewer pointed at this very site, published with its own findings intact.
Open in a new tab · Download the sealed HTML · 11 KB · prints to PDF · makes no network calls
SHPBL itself · as the report states it
Method sound, hygiene not
- Findings
- 9, printed unedited
- High severity
- 2 — ignore rules, multi-word search
- Fixed in
- MCP server 1.13.0
- Host lines changed by the run
- 0
Every figure is copied from the sealed report it links to.
Tested against real repositories
Five public repositories we do not control — DVWA, DeepSeek-V3, Mindustry, n8n, OpenClaw — and a sixth run against this site. Each verdict below is the words the report uses, and each links to the complete report. No run changed a line of its host.
Conditional
DVWA
Buy conditionally
A host that is supposed to stay broken. The only way to prove the method does not lie about security.
Engineered rows screened: 1,117 / 1,117
Conditional
DeepSeek-V3
Proceed — external layer, not a rewrite
The hardest possible flattery test: a world-class ML repository where the wrong answer is 'add our stuff to the model'.
Engineered rows parsed: 1,117 / 1,117
Hold
Mindustry
Hold / conditional buy
The run that argues against the purchase — kept in unedited, because a library that never says no cannot be trusted when it says yes.
Recommended components: 9 of 41 read in full
Recommended
n8n
Buy
A large commercial monorepo with 87 workspaces and mixed licences — the run that proves the method survives real-world licence complexity.
Recommended components: 8
Conditional
OpenClaw
Buy conditionally
A host that already has memory, agents, sandboxing and a dreaming engine — so the run had to find the delta or admit there wasn't one.
Verdict: Buy conditionally at $499
Conditional
SHPBL itself
Method sound, hygiene not
Five runs read other people's repositories. The sixth reads ours — the only study where printing the result cost the author something.
Findings: 9, printed unedited
Why we publish the negative verdicts
5 of the 6 runs did not return a clean “buy”
one is an outright hold. four are conditional. One refused to certify anything secure and left a deliberately vulnerable host vulnerable. SHPBL is built to reject unnecessary intervention: a run does not have to recommend more software to have worked, and “don't touch this, it already works” is a real result. That is the reason a catalogue of 1,000+ engineered components and 3,000+ runnable capability units can be trusted near your code — almost all of it is rejected on any given repository.
Free means free: no key, no card, nothing written to your repository, nothing retained.
Why this is not the tool you already have
Most tools produce more code, or more findings. SHPBL produces a decision with its evidence attached — and, when you are licensed, engineered capability you keep.
Named comparisons, with our own gaps included: SHPBL vs GitHub Copilot · SHPBL vs Bito · How to choose a repository audit tool
Instead of · A coding assistant
Generates a plausible implementation on demand, with no record of its reasoning, provenance, or future compatibility.
Attaches a permanent evidence capsule to every change: source, parents, licence status, and a machine-readable contract you can verify six months later.
Instead of · A static analyser or scanner
Returns a list of findings, ordered by its own severity model, and leaves the judgement, the ordering and the repair to you.
Returns one sealed report: verdict, findings with file and line, a ranked repair order, and the capabilities the repository already contains — and is allowed to conclude that nothing should be touched.
Instead of · An audit engagement
Produces a document at a point in time. Re-reading the same repository six months later costs the engagement again.
Is a method you re-run yourself from the chatbot, the HTTP API or the files you own, on any repository, as often as you like.
Instead of · Your own docs and wiki
Describes intent in prose that drifts from the code the week after it is written, and cannot be reasoned over by an agent.
Harvests what a run learned into machine-readable capability records with contracts, verification status and claim ceilings — a library you keep and reuse on the next repository.
Why you can point this at your code
Six commitments, each one checkable on this site rather than asserted here. If any link below does not show what this claims, that is a bug and we want to hear about it.
Nothing is written to your repository without an authorisation you issue
A run reaching the build or composition stage must obtain a signed, expiring, single-use Build Authorization bound to the caller. The server refuses the write when it is missing — this is enforced in the execution path, not stated in a prompt.
Every release is sealed and the seals are published
Each archive carries a SHA-256 checksum recorded before it ships, so the file you download can be verified against the one we published.
The failures are published alongside the successes
Real runs that returned a hold or a conditional verdict are shown with their reports intact, including the run pointed at this very site.
A free run diagnoses, then stops
A keyless run audits your repository, produces the ranked repair plan, and walks the harvest, then stops before either library — the engineered component catalogue and the runnable capability library — is searched. No composition, and nothing kept but temporary pacing data. Composition and retention are what a paid tier adds.
The licence is public before you pay
The commercial terms for the library you own are readable in full on this site, not delivered after checkout.
A person answers
One maintainer, one address, and a 14-day refund on both the monthly plan and the $499 library. No support tier to buy.
Two meanings. One name.
SHIPPABLE™
We ship software to you. You use it to build, then confidently ship your software to the world.
SHAPEABLE
Your purchase also puts software into the hands of a nonprofit you choose, helping them shape the part of the world they serve.
Those two loops are the reason the company exists — and together, they are how we shape the world.
The library, in numbers
- 0+
- Engineered components
- 0+
- Capability units
- 0
- Originating projects
- 0
- Strategic volumes
Admitted, named software components in the shipped catalogue.
Runnable capability units your agent composes from, counted apart from the catalogue.
One continuous software lineage.
Free to read. No email required.
Current exact release counts → View the release manifest
Three libraries. One set.
Think, evaluate, build. Two of the three are free to read right now; the third is the library of finished components every run is checked against, and it ships inside the set you keep.
THINK
Strategic Master Library™
Seven volumes covering building, strategy, experimentation, durability, stewardship, and what the act of building can make possible.
EVALUATE
Evaluation Master Library™
Give it to your coding agent. It studies your repository first, identifies what works and what doesn't, and determines what should — and should not — change.
BUILD
Collective Master Library™
The capability corpus: engineered software components and the runnable capability units they compose from, derived across 29 originating projects.
Strategic + Evaluation + Collective
= The Master Library Set
Delivered together through The Complete Master Library™
Live · The Discovery Ledger
Watch the library fill its own gaps
The discovery machine watches what people asked this library for and did not get, then collides the capabilities it owns — thousands of combinations at a time — until a chain emerges that answers the gap with new software. No model writes it. No model approves it. A human accepts each row by hand, and you can read the record.
Own software again
Somewhere along the way, buying software started meaning renting permission to use it. SHPBL uses a different model. Purchase the Complete Master Library once and receive a perpetual licence to that release under the supplied commercial terms. The monthly plan exists for people who want the library without the artifact — not as a tollbooth on something you already bought.
You have the software.
You have the license.
Build with it. Ship with it.
- No mandatory subscription to keep using the release you purchased.
- No SHPBL API required for the licensed software to operate.
- No SHPBL runtime tollbooth between you and the products you build.
- Future major releases are optional upgrades.
- The purchased release does not require a SHPBL subscription, SHPBL API, or runtime permission service to continue operating.
- Build with it under the terms of the supplied Perpetual Edition License 1.0.
Your rights are defined by LicenseRef-CMPSBL-Perpetual-1.0. Read the actual license before purchase.
The stewardship program
One purchase. Two licensed editions.
You receive immediate access to your purchased release, and the eligible nonprofit you choose receives immediate access to its licensed edition. Then we personalise and mail a tangible edition to each of you.
- 01
You choose the mission.
- 02
We prepare the Stewardship Edition.
- 03
We ship it on your behalf.
Not leftovers. A real licensed Stewardship Edition built from the same Complete Master Library — provided so an organisation doing meaningful work can keep building too.
Someone chose you.
Where to go next
Four ways to keep reading: what the library contains, how a run is made, how to check the claims, and who stands behind them.
The library
What you can read, borrow or own.
Run it
Three transports, one method.
Proof
Check the claims before you trust them.
The house
Who wrote this, and on what terms.
We ship software.
Then you ship software.
Together, we shape the world.
Start with a free run — it costs nothing and tells you the truth about your repository. For $39 a month, licensed runs write back into your repository and the capability they harvest stays yours to reuse. Own the library outright for $499.
One-time purchase · perpetual rights to the purchased release under its license.