Skylos

B
B tier on Static Application Security Testing SoftwareScore 7.4 · #1 of 24
Android app
Not listed
Free plan
Yes
Runs on
api, Browser extension, Linux, Mac, self-hosted, Web, Windows
skylos.dev
The Skylos homepage

Summary

Skylos is an open-source static analysis tool for finding security regressions, exposed secrets, dead code, quality issues, and mistakes introduced by AI. It analyzes Python, JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment configuration, though analysis depth varies by language. Its CLI runs locally without an account and supports local scans and CI checks. A free VS Code extension provides inline diagnostics and optional AI verification using OpenAI or Anthropic API keys. Cloud features include GitHub pull request workflows, OIDC identity, and optional Slack or Discord notifications. A normal CLI scan stays on your machine; Cloud receives scan data when a report is uploaded, a cloud action is triggered, or the public scan endpoint is used. Uploaded reports may contain findings, file paths, line numbers, snippets, and scan metadata. The Free plan includes one cloud project, 10 stored scans, and 7-day history. One-time credit packs start at 9.00 USD and include Pro access for a stated period. Skylos says it does not currently claim SOC 2, ISO 27001, or CSA STAR certification.

Who it is for

Skylos suits developers and teams seeking local static analysis and CI checks. Its VS Code extension is described for Python teams already using Ruff, Pylint, or Mypy.

What is good

  • CLI scans run locally without an account.
  • Supports local scanning and CI checks.
  • Free VS Code extension offers inline diagnostics.
  • Optional GitHub workflows and Slack or Discord notifications.
  • Analysis covers multiple languages and deployment configuration.

What to know first

  • Analysis depth varies by language.
  • Free cloud plan allows one project and 10 stored scans.
  • Skylos does not currently claim SOC 2, ISO 27001, or CSA STAR certification.
  • Uploaded reports may include findings, paths, line numbers, and snippets.

Everything Xiaomi review

Skylos: the full review

Skylos offers local and CI static analysis, with optional editor and cloud features. Consider the cloud plan’s storage limits and report contents when deciding whether to upload scan data.

Overview

Skylos is an open-source static analysis tool for finding security regressions, exposed secrets, dead code, quality problems and mistakes introduced by AI. It suits teams that want local scans or CI checks, particularly Python teams already using Ruff, Pylint or Mypy. Its local-first CLI is a practical starting point; cloud workflows add collaboration and history, but uploading reports has privacy and retention trade-offs.

Key features

The CLI runs locally without an account, so teams can scan code and add CI checks without sending reports to Skylos. Analysis covers Python, JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell and deployment configuration, with depth varying by language. That breadth is useful for mixed-language repositories, though teams should not assume equal coverage across every language.

The free VS Code extension adds inline diagnostics and optional AI verification through OpenAI or Anthropic API keys. GitHub pull request workflows, OIDC identity, and optional Slack and Discord notifications are cloud features. Local MCP tools cover analysis, security, quality and secret scanning; remediation uses credits, so it may add cost when teams use it.

A normal CLI scan stays on the user's machine. Data reaches Cloud when a report is uploaded, a cloud action is triggered or the public scan endpoint is used. Reports may contain findings, severity, rule identifiers, paths, line numbers, snippets, attribution and scan metadata, with provenance or defense evidence optional. Skylos describes role-based permissions, hashed project API keys, restricted GitHub OIDC uploads, bounded report ingestion and security headers. It does not claim SOC 2, ISO 27001 or CSA STAR certification.

Pricing

The free plan costs 0.00 USD per free. It combines local CLI scans without login with one cloud project, 10 stored scans and seven-day history, making it suitable for individual evaluation or light use rather than long-term team reporting.

Paid credit packs are one-time purchases, not recurring subscriptions: Starter costs 9.00 USD per once for 500 credits and 30 days of Pro access; Builder is 39.00 USD per once for 2,500 credits and 90 days; Team is 129.00 USD per once for 10,000 credits and 180 days; Scale is 499.00 USD per once for 50,000 credits and 365 days. Credits do not expire, but Pro access does, so buyers should distinguish the lasting credit balance from the time-limited access.

Workspace includes 10 projects, 500 stored scans per project and 90-day history. Enterprise has custom pricing, with 9,999 projects, 10,000 stored scans, 365-day history, unlimited credits, priority support and an SLA. The available packs suit intermittent or finite credit needs; teams requiring greater scale, retention or service commitments should consider Enterprise.

Platforms

Skylos supports API, extension, Linux, macOS, self-hosted, web and Windows environments. Its hybrid deployment model pairs local and CI use with optional cloud features, letting teams keep ordinary CLI scans local while opting into cloud workflows.

Who it's for

Skylos is best suited to developers and teams that want static analysis in local workflows, CI or VS Code, especially Python teams already using Ruff, Pylint or Mypy. Its cloud tier is a better fit when pull request workflows, notifications and stored scan history matter. Teams that require a named security certification should look elsewhere.

Pros and cons

  • Pro: Local CLI scans need no account and stay on-device unless a cloud action or upload is used, giving teams a clear local workflow.
  • Pro: Language coverage spans common application and deployment code, with CI, IDE and MCP entry points for different workflows.
  • Pro: Credit purchases are one-time and credits do not expire, so occasional users need not commit to a recurring plan.
  • Con: Cloud storage is capped by plan and history length, limiting long-term review on Free and Workspace.
  • Con: Uploaded reports can include source snippets and file-level details, which may require review before a team enables cloud features.
  • Con: Analysis depth varies by language, and Skylos does not claim SOC 2, ISO 27001 or CSA STAR certification.

Alternatives

For another free, open-source choice with CLI and platform components under Apache License 2.0, consider Horusec. Puma Scan offers a free Community plan and a 299.00 USD per year End User plan; it may suit readers comparing a paid annual license.

Semgrep Code is worth comparing for its free Code and Supply Chain edition, capped at 10 repositories, 10 contributors and 60 AI credits. For a dedicated open-source static analysis engine and CLI, OpenGrep is a free option.

Snyk Open Source focuses on software composition analysis; its free plan covers five projects. For teams seeking a paid web application and API testing product, Veracode DAST is another option. PVS-Studio and Black Duck Coverity are further alternatives for readers comparing static analysis tools.

See more tools in Static Application Security Testing Software.

Verdict

Choose Skylos if you want a local-first analyzer with CI and editor support, broad language coverage, and optional cloud workflows without a recurring credit-pack commitment. Its strongest case is keeping routine scans local while adding cloud features selectively. Look elsewhere if your team needs a recognized security certification, consistently deep analysis across every supported language, or cloud retention beyond the plan limits.

Skylos plans and pricing

All plans
Free Free Local CLI scans without login · Cloud: 1 project · 10 stored scans · 7-day history skylos.dev · 30 Sept 2026
Starter credit pack $9 once 500 credits; one-time purchase; credits do not expire; Pro access for 30 days 500 credits · 30 days Pro access docs.skylos.dev · 30 Sept 2026
Builder credit pack $39 once 2,500 credits; one-time purchase; credits do not expire; Pro access for 90 days 2,500 credits · 90 days Pro access docs.skylos.dev · 30 Sept 2026
Team credit pack $129 once 10,000 credits; one-time purchase; credits do not expire; Pro access for 180 days 10,000 credits · 180 days Pro access docs.skylos.dev · 30 Sept 2026
Scale credit pack $499 once 50,000 credits; one-time purchase; credits do not expire; Pro access for 365 days 50,000 credits · 365 days Pro access docs.skylos.dev · 30 Sept 2026
Enterprise Not published Custom pricing Unlimited credits · 365-day retention · Priority support and SLA docs.skylos.dev · 30 Sept 2026

Compared on static application security testing software

Free plan
Yesskylos.dev
Analysis target
sourceskylos.dev
Supported languages
11 languagesskylos.dev
IDE support
Yesskylos.dev
CI/CD support
Yesskylos.dev
Deployment
hybridskylos.dev
SCA included
Yesskylos.dev
Fix guidance
Yesskylos.dev

Facts

What it does
Skylos is an open-source static analysis tool that finds security regressions, secrets, dead code, quality issues, and mistakes introduced by AI.skylos.dev · 30 Sept 2026
Local and CI use
The CLI runs locally without an account and supports local scanning and CI checks.docs.skylos.dev · 30 Sept 2026
IDE integration
The free VS Code extension provides inline diagnostics and optional AI verification using OpenAI or Anthropic API keys.skylos.dev · 30 Sept 2026
Cloud integrations
Cloud features include GitHub pull request workflows and OIDC identity, plus optional Slack and Discord notifications.skylos.dev · 30 Sept 2026
MCP support
The docs list local MCP tools for analysis, security scanning, quality checks, and secret scanning, and a credit-charged remediation tool.docs.skylos.dev · 30 Sept 2026
Local data handling
A normal CLI scan stays on the user's machine; Cloud receives scan data when a user or workflow uploads a report, triggers a cloud action, or uses the public scan endpoint.skylos.dev · 30 Sept 2026
Cloud data
Uploaded reports may include findings, severity, rule IDs, file paths, line numbers, snippets, attribution, scan metadata, and optional provenance or defense evidence.skylos.dev · 30 Sept 2026
Security controls
The Trust Center describes role-based permissions, hashed project API keys, restricted GitHub OIDC uploads, bounded report ingestion, and security headers.skylos.dev · 30 Sept 2026
Compliance
Skylos says it does not currently claim SOC 2, ISO 27001, or CSA STAR certification.skylos.dev · 30 Sept 2026
Plan limits
The Workspace tier includes 10 projects, 500 stored scans per project, and 90-day history; Enterprise lists 9,999 projects, 10,000 stored scans, and 365-day history.skylos.dev · 30 Sept 2026
Support
The security page says vulnerability reports are acknowledged within 2 business days with an initial triage update within 5 business days, and that there is no paid bug bounty program.skylos.dev · 30 Sept 2026
Who it is for
The VS Code page describes the extension for Python teams already using Ruff, Pylint, or Mypy.skylos.dev · 30 Sept 2026

Best Skylos alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Skylos yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources