Skylos
Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed
About
Skylos is ranked #1 of 24 in static application security testing software on Inferse. It runs on API, Browser extension, Linux, macOS, Self-hosted, Web, Windows. There is a free plan. A free trial is offered.
Compared on static application security testing software
- Free plan
- Yesskylos.dev
- Analysis target
- sourceskylos.dev
- Supported languages
- 11 languagesskylos.dev
- IDE support
- Yesskylos.dev
- CI/CD support
- Yesskylos.dev
- Deployment
- hybridskylos.dev
- SCA included
- Yesskylos.dev
- Fix guidance
- Yesskylos.dev
Facts
- What it does
- Skylos is an open-source static analysis tool that finds security regressions, secrets, dead code, quality issues, and mistakes introduced by AI.skylos.dev · 30 Sept 2026
- Supported languages
- It analyzes Python, JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment configuration, with analysis depth varying by language.skylos.dev · 30 Sept 2026
- Local and CI use
- The CLI runs locally without an account and supports local scanning and CI checks.docs.skylos.dev · 30 Sept 2026
- IDE integration
- The free VS Code extension provides inline diagnostics and optional AI verification using OpenAI or Anthropic API keys.skylos.dev · 30 Sept 2026
- Cloud integrations
- Cloud features include GitHub pull request workflows and OIDC identity, plus optional Slack and Discord notifications.skylos.dev · 30 Sept 2026
- MCP support
- The docs list local MCP tools for analysis, security scanning, quality checks, and secret scanning, and a credit-charged remediation tool.docs.skylos.dev · 30 Sept 2026
- Local data handling
- A normal CLI scan stays on the user's machine; Cloud receives scan data when a user or workflow uploads a report, triggers a cloud action, or uses the public scan endpoint.skylos.dev · 30 Sept 2026
- Cloud data
- Uploaded reports may include findings, severity, rule IDs, file paths, line numbers, snippets, attribution, scan metadata, and optional provenance or defense evidence.skylos.dev · 30 Sept 2026
- Security controls
- The Trust Center describes role-based permissions, hashed project API keys, restricted GitHub OIDC uploads, bounded report ingestion, and security headers.skylos.dev · 30 Sept 2026
- Compliance
- Skylos says it does not currently claim SOC 2, ISO 27001, or CSA STAR certification.skylos.dev · 30 Sept 2026
- Plan limits
- The Workspace tier includes 10 projects, 500 stored scans per project, and 90-day history; Enterprise lists 9,999 projects, 10,000 stored scans, and 365-day history.skylos.dev · 30 Sept 2026
- Support
- The security page says vulnerability reports are acknowledged within 2 business days with an initial triage update within 5 business days, and that there is no paid bug bounty program.skylos.dev · 30 Sept 2026
- Who it is for
- The VS Code page describes the extension for Python teams already using Ruff, Pylint, or Mypy.skylos.dev · 30 Sept 2026
Best Skylos alternatives
See all 12
7.4 Snyk Open Source $25/mo first paid tier Free plan
7.3 Horusec Free free plan, no paid price published Free plan
7.3 Semgrep Code $30/mo first paid tier Free plan
6.9 Veracode DAST See plans price on the maker's page Free trial
6.8 Checkmarx API Security See plans price on the maker's page
6.0 Puma Scan $24.92/mo first paid tier Free plan Where it ranks on Inferse
Sources
- skylos.dev· checked 30 Sept 2026
- docs.skylos.dev· checked 30 Sept 2026
- skylos.dev/vscode· checked 30 Sept 2026
- skylos.dev/trust· checked 30 Sept 2026
- docs.skylos.dev/billing· checked 30 Sept 2026
- skylos.dev/security· checked 30 Sept 2026
- skylos.dev/workspace-governance· checked 30 Sept 2026


