Skylos is an open-source static analysis tool for finding security regressions, exposed secrets, dead code, quality problems, and mistakes introduced by AI. It analyzes Python, JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment configuration, with analysis depth varying by language. Its CLI runs locally without an account and supports local scans and CI checks. A free VS Code extension provides inline diagnostics and optional AI verification using OpenAI or Anthropic API keys. Cloud features include GitHub pull request workflows, OIDC identity, and optional Slack or Discord notifications. A normal CLI scan stays on the user's machine; Cloud receives scan data when a report is uploaded, a cloud action is triggered, or the public scan endpoint is used. Uploaded reports may contain findings, severity, rule IDs, file paths, line numbers, snippets, attribution, scan metadata, and optional provenance or defense evidence. The Free plan includes one cloud project, 10 stored scans, and seven-day history. One-time credit packs start at 9.00 USD and provide Pro access for a stated period. Skylos says it does not currently claim SOC 2, ISO 27001, or CSA STAR certification.
Who it is for
Skylos may suit developers and teams looking for local static analysis or CI checks across its supported languages. Its VS Code extension is described for Python teams already using Ruff, Pylint, or Mypy.
What is good
- CLI scans run locally without an account.
- Supports local scanning and CI checks.
- VS Code extension provides inline diagnostics.
- Optional AI verification uses user-provided API keys.
- Free plan includes one cloud project.
What to know first
- Analysis depth varies by language.
- Cloud receives scan data when reports or actions are uploaded.
- Skylos does not claim SOC 2, ISO 27001, or CSA STAR certification.
- Free cloud history lasts seven days.
The Geeks Club review
Skylos: the full review
Skylos offers local scanning, editor diagnostics, and cloud workflows, with clear distinctions between local and uploaded scan data. Teams evaluating it should account for language-specific analysis depth and the cloud plan's storage and history limits.
Overview
Skylos is an open-source static analysis tool for detecting security regressions, secrets, dead code, quality issues and errors introduced by AI. It is best suited to teams that want local scanning and CI checks, particularly Python teams already using Ruff, Pylint or Mypy. Its local CLI is the clearest reason to choose it; teams that need uniform analysis across languages or certified compliance should look elsewhere.
Key features
The CLI runs locally without an account, which makes it a practical way to add checks without adopting a hosted workflow. Skylos analyzes Python, JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell and deployment configuration. That breadth may suit mixed-language repositories, but varying analysis depth means it is not a guarantee of equally strong coverage for every codebase.
The free VS Code extension provides inline diagnostics and optional AI verification through OpenAI or Anthropic API keys. Skylos also offers GitHub pull request workflows and OIDC identity in Cloud, with optional Slack and Discord notifications. Its local MCP tools cover analysis, security, quality and secret scanning; remediation consumes credits, so teams should treat that capability as a metered workflow.
A normal CLI scan stays on the user's machine. Data goes to Cloud when a user or workflow uploads a report, triggers a cloud action or uses the public scan endpoint. Uploaded reports may contain findings, severity, rule IDs, paths, line numbers, snippets, attribution and scan metadata, as well as optional provenance or defense evidence. The Trust Center describes role-based permissions, hashed project API keys, restricted GitHub OIDC uploads, bounded report ingestion and security headers. Those controls are useful, but Skylos does not claim SOC 2, ISO 27001 or CSA STAR certification. Its security page says vulnerability reports are acknowledged within 2 business days, with an initial triage update within 5 business days; there is no paid bug bounty program.
Pricing
Skylos uses a free tier and one-time credit packs rather than a conventional monthly subscription. The Free plan costs 0.00 USD per free and includes local CLI scans without login, plus Cloud access for 1 project, 10 stored scans and 7-day history. That is enough to try local scanning, but the small cloud allowance limits its usefulness for teams that want ongoing history.
The Starter credit pack costs 9.00 USD per once for 500 credits and 30 days of Pro access. Builder costs 39.00 USD per once for 2,500 credits and 90 days; Team costs 129.00 USD per once for 10,000 credits and 180 days; Scale costs 499.00 USD per once for 50,000 credits and 365 days. Credits do not expire, but Pro access does, so buyers should distinguish the lasting credit balance from the time-limited access. Larger packs offer more credits and a longer access window, but require a larger one-time outlay.
Enterprise has custom pricing and includes unlimited credits, 365-day retention, priority support and an SLA. The Workspace tier includes 10 projects, 500 stored scans per project and 90-day history; Enterprise lists 9,999 projects, 10,000 stored scans and 365-day history. These cloud limits matter to teams that rely on retained scans for review. The Free tier and 7-day trial offer a low-commitment start, while the credit packs suit users who prefer one-time purchases over a recurring fee.
Platforms
Skylos is offered across API, extension, Linux, macOS, self-hosted, web and Windows. CLI use is local, while uploaded reports and cloud actions enable hosted workflows. It supports CI/CD and IDE use, and its deployment model is hybrid. Software composition analysis is included, and fix guidance is available.
Who it's for
Skylos makes most sense for developers and teams seeking local checks, CI integration and a VS Code workflow, especially Python teams already using Ruff, Pylint or Mypy. Mixed-language teams can use its broad language coverage, provided they account for differences in analysis depth. Teams that require certified compliance, longer retention than their plan allows or no report uploads to Cloud should evaluate those requirements before adopting the hosted features.
Pros and cons
- Pro: Local CLI scans need no account and keep normal scan data on the user's machine, a useful fit for teams prioritizing local workflows.
- Pro: The free VS Code extension, CI checks and broad language support give developers several ways to bring analysis into existing work.
- Pro: One-time credit packs avoid recurring billing, and unused credits do not expire.
- Con: Analysis depth varies by language, making coverage less predictable for repositories spanning several languages.
- Con: The Free cloud plan is capped at 1 project, 10 scans and 7 days of history, which is restrictive for sustained team use.
- Con: Pro access in paid packs expires after 30 to 365 days, and Cloud workflows involve uploading report data that may include code snippets and file paths.
- Con: Skylos does not claim SOC 2, ISO 27001 or CSA STAR certification, which may rule it out for teams with those requirements.
Alternatives
For a broader shortlist, browse Static Application Security Testing Software.
- Puma Scan is another freemium option with a free Community plan and a 299.00 USD per year End User plan.
- Snyk Open Source is worth considering when its stated focus on software composition analysis is a closer fit; its Free plan covers 5 projects at 0.00 USD per month.
- Horusec is a free, open-source alternative with CLI and platform components.
- Semgrep Code is another option; its Free Edition includes Code and Supply Chain for up to 10 repositories and 10 contributors, plus 60 AI credits.
- Veracode DAST is an alternative for readers considering web application and API testing.
- PVS-Studio is another static analysis option with custom-priced Team and Enterprise plans.
- Flawfinder is a free GPL-2.0+ open-source tool for readers who want a no-cost alternative.
- OpenGrep is a free, open-source static analysis engine with a CLI.
Verdict
Choose Skylos if you want local-first scanning, CI checks and a free VS Code extension, with optional cloud collaboration when its upload and retention terms suit your team. Its language range and credit packs are useful, but varying analysis depth, limited free cloud history and the absence of named compliance certifications are reasons to compare alternatives before making it a team-wide choice.
Skylos plans and pricing
All plansCompared on static application security testing software
- Free plan
- Yes
- Analysis target
- source
- Supported languages
- 11 languages
- IDE support
- Yes
- CI/CD support
- Yes
- Deployment
- hybrid
- SCA included
- Yes
- Fix guidance
- Yes



