Skylos MCP server
Dead code, security, secrets detection and code quality for Python, TypeScript, Go.
838 stars17k downloads/wk
Reviews
Write oneNobody has reviewed Skylos yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Skylos tools (6)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
_has_typed_argsCheck if function arguments have type annotations.
analyzequality_checkremediatesecrets_scansecurity_scan
Public scan report
scanner v0.1.10 · 2026-09-28 · same rubric, same numbers if you re-run it
- Code scan153 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (2)
- mediumeval / new Function used
exec.evalskylos-3.5.10/skylos/cicd/review.py: …str, str] = { "SKY-D201": "Replace `eval()` with `json.loads()`, `ast.literal_eva… - mediumsubprocess with shell=True
exec.shell-trueskylos-3.5.10/skylos/cli.py: …SKY-D209": "Shell execution (subprocess shell=True)", "SKY-D210": "TLS verific…
Install Skylos in Claude Code, Cursor or VS Code
claude mcp add skylos -- uvx skylos
What the publisher says
From the Skylos repository's README, as published. We do not edit it. Read it on GitHub
Skylos Open-source, local-first checks for dead code, security issues, secrets, quality regressions, and AI-code mistakes before merge.
Website | Docs | Repo Map | Quick Start | GitHub Action | VS Code Extension | Real-World Results | Benchmarks | Roadmap | Contributing
English | Deutsch | 简体中文 | Translations
What Is Skylos?
Skylos is an open-source static analysis CLI for Python, TypeScript, JavaScript, Java, Go, Kotlin, PHP, Rust, Dart, C#, C++, Shell, and deployment config. It runs locally by default and can also be used as a CI/CD PR gate.
Use Skylos when you want one command to check a repo or pull request for:
invented package APIs, and impossible dependency versions
- dead code and unused files
- security flaws and dangerous data flows
- secrets and dependency CVEs
- CI/CD and edge-device deployment misconfigurations
- quality regressions such as complexity, duplicate branches, and deep nesting
- common AI-generated code mistakes, including missing guards, fake helpers,
- LLM app risks such as unsafe tool use and missing output validation
Choose the Right Command
Each command answers a different question. The source scan requires PATH. Bracketed paths on verify, suite, defend, and clean default to the current directory. suite and defend require a directory; verify and clean also accept a file.
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Skylos: common questions
- Is Skylos MCP server safe?
- With care: it is graded C, so read the findings first (68/100). Read the Skylos safety report
- How do I install Skylos?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Skylos need an API key?
- Yes. The registry entry asks for
SKYLOS_API_KEY. - Is Skylos maintained?
- The last commit was in the last day (2026-09-28). The latest release is v3.5.10.
- What can I use instead of Skylos?
- Servers from other publishers that do the same job: Wireshark MCP server, SonarQube MCP Server and Jikida MCP server. Compare all Skylos alternatives.
Alternatives to Skylos
Same job from other publishers: the closest match first, then the best rated.
- WiresharkProfessional network analysis with tshark. Security audits, deep-dives, and threat detection.not reviewedEstablishedA
- SonarQube MCP ServerAnalyze code quality and security with SonarQube Server or Cloud directly in AI assistants.not reviewedGrowingB
- JikidaSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.not reviewedGrowingA
- grim-mcpSecurity audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.not reviewedGrowingC
Black Duck Security ScannerAI-powered security scanning using Black Duck Signal for vulnerability detection.not reviewedGrowingA