Skylos

No phone app

  • Recognised40% of the score20
  • Phone app26% of the score0
  • Documented20% of the score100
  • Free plan14% of the score100
Free plan
Yes
Runs on
api, Browser extension, Linux, Mac, self-hosted, Web, Windows

Summary

Skylos is an open-source static analysis tool for finding security regressions, exposed secrets, dead code, quality problems, and mistakes introduced by AI. It analyzes Python, JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment configuration, though analysis depth differs by language. Its CLI can run locally without an account and supports local scans and CI checks. A free VS Code extension provides inline diagnostics and optional AI verification using OpenAI or Anthropic API keys. Cloud features include GitHub pull request workflows, OIDC identity, and optional Slack or Discord notifications. A normal CLI scan stays on the user's machine; Cloud receives scan data when a report is uploaded, a cloud action is triggered, or the public scan endpoint is used. Uploaded reports may include findings, file paths, line numbers, snippets, and scan metadata. The free plan includes one cloud project, 10 stored scans, and seven days of history. One-time credit packs start at 9.00 USD and include Pro access for a stated period. Skylos says it does not currently claim SOC 2, ISO 27001, or CSA STAR certification.

Who it is for

Skylos may suit developers who want local or CI analysis, including Python teams already using Ruff, Pylint, or Mypy. Its cloud workflows may also fit teams using GitHub pull requests and optional chat notifications.

What is good

  • CLI scans run locally without an account.
  • Supports local scans and CI checks.
  • Free VS Code extension provides inline diagnostics.
  • Cloud supports GitHub pull request workflows and OIDC.
  • One-time credit packs start at 9.00 USD.

What to know first

  • Analysis depth varies by language.
  • Free cloud plan has one project and 10 stored scans.
  • Uploaded cloud reports may include code snippets and file paths.
  • No current SOC 2, ISO 27001, or CSA STAR claim.

Verdict

Skylos offers local static analysis alongside optional cloud workflows and a VS Code extension. Consider where scan data goes when using cloud actions, and note the stated limits and certification status.

Skylos plans and pricing

All plans
Free Free Local CLI scans without login · Cloud: 1 project · 10 stored scans · 7-day history skylos.dev · 30 Sept 2026
Starter credit pack $9 once 500 credits; one-time purchase; credits do not expire; Pro access for 30 days 500 credits · 30 days Pro access docs.skylos.dev · 30 Sept 2026
Builder credit pack $39 once 2,500 credits; one-time purchase; credits do not expire; Pro access for 90 days 2,500 credits · 90 days Pro access docs.skylos.dev · 30 Sept 2026
Team credit pack $129 once 10,000 credits; one-time purchase; credits do not expire; Pro access for 180 days 10,000 credits · 180 days Pro access docs.skylos.dev · 30 Sept 2026
Scale credit pack $499 once 50,000 credits; one-time purchase; credits do not expire; Pro access for 365 days 50,000 credits · 365 days Pro access docs.skylos.dev · 30 Sept 2026
Enterprise Not published Custom pricing Unlimited credits · 365-day retention · Priority support and SLA docs.skylos.dev · 30 Sept 2026

Compared on static application security testing software

Free plan
Yesskylos.dev
Analysis target
sourceskylos.dev
Supported languages
11 languagesskylos.dev
IDE support
Yesskylos.dev
CI/CD support
Yesskylos.dev
Deployment
hybridskylos.dev
SCA included
Yesskylos.dev
Fix guidance
Yesskylos.dev

Facts

What it does
Skylos is an open-source static analysis tool that finds security regressions, secrets, dead code, quality issues, and mistakes introduced by AI.skylos.dev · 30 Sept 2026
Local and CI use
The CLI runs locally without an account and supports local scanning and CI checks.docs.skylos.dev · 30 Sept 2026
IDE integration
The free VS Code extension provides inline diagnostics and optional AI verification using OpenAI or Anthropic API keys.skylos.dev · 30 Sept 2026
Cloud integrations
Cloud features include GitHub pull request workflows and OIDC identity, plus optional Slack and Discord notifications.skylos.dev · 30 Sept 2026
MCP support
The docs list local MCP tools for analysis, security scanning, quality checks, and secret scanning, and a credit-charged remediation tool.docs.skylos.dev · 30 Sept 2026
Local data handling
A normal CLI scan stays on the user's machine; Cloud receives scan data when a user or workflow uploads a report, triggers a cloud action, or uses the public scan endpoint.skylos.dev · 30 Sept 2026
Cloud data
Uploaded reports may include findings, severity, rule IDs, file paths, line numbers, snippets, attribution, scan metadata, and optional provenance or defense evidence.skylos.dev · 30 Sept 2026
Security controls
The Trust Center describes role-based permissions, hashed project API keys, restricted GitHub OIDC uploads, bounded report ingestion, and security headers.skylos.dev · 30 Sept 2026
Compliance
Skylos says it does not currently claim SOC 2, ISO 27001, or CSA STAR certification.skylos.dev · 30 Sept 2026
Plan limits
The Workspace tier includes 10 projects, 500 stored scans per project, and 90-day history; Enterprise lists 9,999 projects, 10,000 stored scans, and 365-day history.skylos.dev · 30 Sept 2026
Support
The security page says vulnerability reports are acknowledged within 2 business days with an initial triage update within 5 business days, and that there is no paid bug bounty program.skylos.dev · 30 Sept 2026
Who it is for
The VS Code page describes the extension for Python teams already using Ruff, Pylint, or Mypy.skylos.dev · 30 Sept 2026

Best Skylos alternatives

See all 12

Where it ranks on Samsung Mobile US Press

Is Skylos yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources