skylos — security grade SAFE, quality 70/100

Security audit verdict: SAFE · quality 70/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by duriantaco · MCP Server · ★ 828

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is skylos safe to install? View the security audit →

About skylos

Skylos Open-source, local-first checks for dead code, security issues, secrets, quality regressions, and AI-code mistakes before merge. Website | Docs | Repo Map | Quick Start | GitHub Action | VS Code Extension | Real-World Results | Benchmarks | Roadmap | Contributing English [Tra

ai-agentsai-code-reviewai-generated-codecode-qualitydead-codedead-code-detectiondevsecopsgithub-actionsgomcp-server

Quick Facts

Stars828
Forks55
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score69.8011597928298/100
Open Issues7
Last Updated2026-09-21
Created2025-04-28
Platformsmcp, python
Est. Tokens~4056k

Compatible Skills

These tools work well together with skylos for enhanced workflows:

  • Gito — semantic(0.29)+complementary+rare_topics+same_lang+similar_pop+shared_platform (69%)
  • ai-review — semantic(0.19)+complementary+rare_topics+same_lang+similar_pop+shared_platform (61%)
  • slowql — semantic(0.18)+complementary+rare_topics+same_lang+similar_pop+shared_platform (60%)
  • Auditor — semantic(0.28)+complementary+rare_topics+same_lang+similar_pop+shared_platform (59%)
  • fossil-mcp — semantic(0.53)+rare_topics+similar_pop+shared_platform (54%)

skylos alternative? Top 6 similar tools

Looking for a skylos alternative? If you're comparing skylos with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • roam-code by Cranot · ⭐ 518

    Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 comman

  • Gito by Nayjest · ⭐ 432

    An AI-powered GitHub code review tool that uses LLMs to detect high-confidence, high-impact issues—such as sec

  • vibe-coding-prompt-template by KhazP · ⭐ 3.1k

    Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs

  • medusa by Pantheon-Security · ⭐ 962

    AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions

  • axon by harshkedia177 · ⭐ 798

    Graph-powered code intelligence engine — indexes codebases into a knowledge graph, exposed via MCP tools for A

  • drift by dadbodgeoff · ⭐ 785

    Codebase intelligence for AI. Detects patterns & conventions + remembers decisions across sessions. MCP server

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is skylos?

skylos is Open-source Python, TypeScript, and Go SAST with dead code detection. Finds secrets, exploitable flows, and AI regressions. VS Code extension, GitHub Action, and MCP server for AI agents.. It is categorized as a MCP Server with 828 GitHub stars.

What programming language is skylos written in?

skylos is primarily written in Python. It covers topics such as ai-agents, ai-code-review, ai-generated-code.

How do I install or use skylos?

You can find installation instructions and usage details in the skylos GitHub repository at github.com/duriantaco/skylos. The project has 828 stars and 55 forks, indicating an active community.

What license does skylos use?

skylos is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to skylos?

The top alternatives to skylos on Agent Skills Hub include roam-code, Gito, vibe-coding-prompt-template. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools