Skylos

Privacy-first SAST tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and code quality issues w

duriantaco 471 ↓ 230k
Claude CodeClaude DesktopGeneric
View source ↗

Skylos is a static analysis security testing (SAST) tool that bridges traditional static analysis with AI agents. It detects dead code, security vulnerabilities (SQL injection, SSRF, secrets), and code quality issues in Python, TypeScript, and Go codebases. The hybrid engine combines AST parsing with optional local or cloud LLM verification to eliminate false positives caused by dynamic language patterns and framework magic. Includes CI/CD integration with GitHub Actions, a VS Code extension, and agentic AI-powered auto-fix capabilities.

Source

Repository: https://github.com/duriantaco/skylos

Maintain Skylos?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

Skylos on getagentictools
[![Skylos on getagentictools](https://getagentictools.com/badge/mcp/duriantaco-skylos.svg)](https://getagentictools.com/mcp/duriantaco-skylos?ref=badge)