Mmcp.market

Skylos MCP server

by duriantaco·io.github.duriantaco/skylos·v3.5.10·838 stars

Dead code, security, secrets detection and code quality for Python, TypeScript, Go.

C68/100grade C
What users say
No reviews yet
Be the first
Safety scan
C68/100

full report

Adoption
Established

838 stars17k downloads/wk

Reviews

Write one

Nobody has reviewed Skylos yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Skylos tools (6)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • _has_typed_args

    Check if function arguments have type annotations.

  • analyze
  • quality_check
  • remediate
  • secrets_scan
  • security_scan

Public scan report

scanner v0.1.10 · 2026-09-28 · same rubric, same numbers if you re-run it

2 medium
  • Code scan153 source files scanned15/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitystatic API keys via environment variables6/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (2)

  • mediumeval / new Function usedexec.eval
    skylos-3.5.10/skylos/cicd/review.py: …str, str] = { "SKY-D201": "Replace `eval()` with `json.loads()`, `ast.literal_eva…
  • mediumsubprocess with shell=Trueexec.shell-true
    skylos-3.5.10/skylos/cli.py: …SKY-D209": "Shell execution (subprocess shell=True)", "SKY-D210": "TLS verific…
Overall 68/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Skylos in Claude Code, Cursor or VS Code

claude mcp add skylos -- uvx skylos
Add to Cursor

What the publisher says

From the Skylos repository's README, as published. We do not edit it. Read it on GitHub

Skylos Open-source, local-first checks for dead code, security issues, secrets, quality regressions, and AI-code mistakes before merge.

Website | Docs | Repo Map | Quick Start | GitHub Action | VS Code Extension | Real-World Results | Benchmarks | Roadmap | Contributing

English | Deutsch | 简体中文 | Translations

What Is Skylos?

Skylos is an open-source static analysis CLI for Python, TypeScript, JavaScript, Java, Go, Kotlin, PHP, Rust, Dart, C#, C++, Shell, and deployment config. It runs locally by default and can also be used as a CI/CD PR gate.

Use Skylos when you want one command to check a repo or pull request for:

invented package APIs, and impossible dependency versions

  • dead code and unused files
  • security flaws and dangerous data flows
  • secrets and dependency CVEs
  • CI/CD and edge-device deployment misconfigurations
  • quality regressions such as complexity, duplicate branches, and deep nesting
  • common AI-generated code mistakes, including missing guards, fake helpers,
  • LLM app risks such as unsafe tool use and missing output validation

Choose the Right Command

Each command answers a different question. The source scan requires PATH. Bracketed paths on verify, suite, defend, and clean default to the current directory. suite and defend require a directory; verify and clean also accept a file.

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Skylos: common questions

Is Skylos MCP server safe?
With care: it is graded C, so read the findings first (68/100). Read the Skylos safety report
How do I install Skylos?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Skylos need an API key?
Yes. The registry entry asks for SKYLOS_API_KEY.
Is Skylos maintained?
The last commit was in the last day (2026-09-28). The latest release is v3.5.10.
What can I use instead of Skylos?
Servers from other publishers that do the same job: Wireshark MCP server, SonarQube MCP Server and Jikida MCP server. Compare all Skylos alternatives.

Alternatives to Skylos

Same job from other publishers: the closest match first, then the best rated.

All Skylos alternatives →
  • Wireshark
    Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
    A
  • SonarQube MCP Server
    Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants.
    B
  • Jikida
    Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.
    A
  • grim-mcp
    Security audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.
    C
  • Black Duck Security Scanner
    AI-powered security scanning using Black Duck Signal for vulnerability detection.
    A

More from duriantaco →