{"repo":"duriantaco/skylos","free":true,"listed":false,"github":"https://github.com/duriantaco/skylos","clone":"git clone https://github.com/duriantaco/skylos.git","description":"Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/","language":"Python","stars":539,"topics":["python","code-quality","dead-code","dead-code-detection","devsecops","sast","static-analysis","typescript","ai-code-review","ai-generated-code"],"license":"Apache-2.0","category":"dev-tools","readme_excerpt":"Skylos Open-source, local-first checks for dead code, security issues, secrets, quality regressions, and AI-code mistakes before merge. Website Docs Repo Map Quick Start GitHub Action VS Code Extension Real-World Results Benchmarks Roadmap Contributing English Deutsch 简体中文 Translations What Is Skylos? Skylos is an open-source static analysis CLI for Python, TypeScript, JavaScript, Java, Go, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment config. It runs locally by default and can also be used as a CI/CD PR gate. Use Skylos when you want one command to check a repo or pull request for: - dead code and unused files - security flaws and dangerous data flows - secrets and dependency CVEs - CI/CD and edge-device deployment misconfigurations - quality regressions such as complexity, duplicate branches, and deep nesting - common AI-generated code mistakes, including missing guards, fake helpers, invented package APIs, and impossible dependency versions - LLM app risks such as unsafe tool use and missing output validation Start In 60 Seconds The default scan focuses on dead code. Add security, secrets, quality, dependency, and AI-defect checks with -a : Run only evidence-backed AI defect checks with: Verify a changed file or range before an agent hands it to review: skylos verify schema version 2 returns pass , fail , or incomplete . incomplete means a requested proof could not be established, such as a third-party TS/JS import, computed namespace member, unsupported language-loca","default_branch":null,"files":null,"tree":[],"storefront":"/r/duriantaco","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/duriantaco/skylos/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}