Skylos
Skylos is a local-first Python static analysis CLI that catches dead code, secrets, and AI-code mistakes before they merge.
Skylos is worth a look for any Python team merging AI-generated PRs faster than they can review. The free CLI is real — `skylos . -a` runs locally with no login, and `--trace` cut false positives in the benchmarks Skylos publishes. It won't replace Semgrep or CodeQL for multi-language SAST, but it catches invented APIs and removed auth checks those tools routinely miss. Run it on one repo first; the CLI proves the value before the $9 cloud layer enters the picture.
Verified 20m ago · liveness 75/100 · cite: rightaichoice.com/tools/skylos
- Python developers using Claude Code, Cursor, Codex, or Copilot on production repos
- Open source maintainers cleaning up dead code across Python libraries
- DevOps engineers adding a lightweight CLI-first PR gate to GitHub Actions
- Teams wanting a low-noise complement to Semgrep or CodeQL on AI-heavy code
- Teams needing mature multi-language SAST parity — Skylos does Python best, other languages vary in depth
- Organizations requiring a GUI-only managed security platform with no CLI in the loop
- Teams whose workflow depends on Jira or issue-tracker integration (not documented)
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip Skylos if you need a multi-language SAST platform covering Java, Go, C#, and TypeScript with equal depth, or a fully managed GUI security console — Skylos is a Python-focused CLI first, with other languages limited.
The $9 Cloud Workspace is a 50-credit starter pack, not a monthly subscription — once your 50 uploads or 25 comparisons are spent you buy more credits, so heavy PR volume costs more than the headline suggests.
Skylos is priced for solo developers and small Python teams: the OSS CLI is free, the Cloud Workspace is a $9 / 50-credit starter pack, and Enterprise is custom with 9,999 projects and 365-day history. Compared to Semgrep or CodeQL enterprise contracts, Skylos is far cheaper but narrower — you are buying Python-specific AI-code coverage, not a multi-language SAST platform.
In short
Skylos — Skylos is a local-first Python static analysis CLI that catches dead code, secrets, and AI-code mistakes before they merge. Best for Python developers using Claude Code, Cursor, Codex, or Copilot on production repos, Open source maintainers cleaning up dead code across Python libraries, DevOps engineers adding a lightweight CLI-first PR gate to GitHub Actions. Free to start; paid plans from $9.
What's new in Skylos
Checked todayAcross the latest 1 update: 1 news mention.
What people actually say about Skylos — is it worth it?
We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.
35 mentions across 4 sources (Hacker News, YouTube, GitHub, Lemmy) · researched Aug 29, 2026.
Average across the 4 sources that answered — each source counts once, not each post.
- +Dead code detection beats Vulture (29/29 vs 24/29) on real libraries.
- +Local-first CLI with no login requirement offers quick, private testing.
- +Unique focus on AI-code mistakes like hallucinated imports and phantom calls.
- +Integrates with Claude Code, Cursor, GitHub Actions, VS Code, and MCP.
- +Confidence scoring and smart tracing aim to keep false positives low.
- −False positives on decorators, TypedDict fields, and closure parameters.
- −Internal package imports incorrectly flagged as undeclared (SKY-D223).
- −macOS terminal probing breaks the TUI progress display.
- −Interactive remove/comment-out fails in WSL2 environments.
- −TUI crashes at startup due to unsupported ListView kwarg.
- • Credit-based cloud pricing may exceed expected costs for high scan volumes.
- • False positives consume manual review time, an implicit cost.
- • Potential need for CI minutes for running tests with smart tracing.
Viability Score
How well maintained and how widely used is Skylos? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: October 2026
How we score →Key Features
- Dead code detection for unused functions, imports, classes, and variables
- SQL injection detection that traces tainted input into string-built queries
- Command injection detection for unsafe shell execution paths
- Hardcoded secrets detection with provider labels (AWS, Stripe) and masked previews
- AI-defect detection for hallucinated imports, invented APIs, and phantom calls
- Removed security control detection (auth decorators, CSRF checks, rate limits)
- Software composition analysis with package reachability and fix versions
- Smart Tracing: runs your test suite to eliminate dead-code false positives
- Diff review that flags risky changes before merge
- GitHub Actions PR gate and CI merge gate
- VS Code extension for in-editor findings
- MCP server support for agent remediation workflows
- Cloud Workspace: stored scans, comparisons, PR comments, and shared triage
- Multi-language analysis for Python, JavaScript/TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, and Shell
- Local-first scan with no code upload and no login
About Skylos
Skylos is an open-source static analysis CLI built for Python developers who let AI agents like Claude Code and Cursor write code faster than they can review it. You install it with `pip install skylos`, then run `skylos . -a` against a repo root for a local audit covering security regressions, hardcoded secrets, dead code, quality issues, dependency risk, and AI-specific defects like invented APIs and hallucinated imports. No login, no upload, no account required for the core scan. The purpose-built checks are what separate it from general SAST. Skylos traces tainted input into string-built queries (finding SKY-D211 SQL injection), flags removed auth decorators and CSRF checks, and catches phantom calls that AI agents confidently invent. Smart Tracing runs your test suite to record which functions are actually called, which cuts false positives from dynamic dispatch. Support doesn't stop at Python either — the vendor now lists analysis for JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment config, though depth varies by language. The cloud layer converts CLI output into a shared workflow: stored scans, PR comments, merge gates, owners, and Slack or Discord alerts, metered by credits rather than seats. Positioning-wise, Skylos sits beside Semgrep and CodeQL rather than replacing them. It's narrower on purpose — the pitch is AI-introduced regressions in the languages your team actually ships. Try the free CLI on one repo before committing to CI.
Behind the Verdict
The honest pitch: AI coding agents make commits that look plausible and aren't. Invented function calls, hallucinated imports, a deleted `@login_required` decorator nobody noticed — that's the class of defect Skylos was built to find, and it's the reason we'd reach for it over a general-purpose scanner on a Python repo. When to pick it: you're on Python 3.10+ (macOS, Linux, or WSL2), you already run Claude Code, Cursor, Codex, or Copilot on a production repo, and your PR review is the bottleneck. The local CLI is free and leaves your code on disk, which matters if legal won't sign off on cloud uploads. `--trace` is the feature that earns its keep — it runs your tests and records which functions actually get called, so dead-code findings stop including half of your plugin system. When to pass: multi-language SAST is not the strongest suit here despite the growing language list, so if you need parity coverage across Java and Go, Semgrep or CodeQL is still the safer pick. Teams that want a GUI-only security platform with no CLI in the loop are also a poor fit — Skylos is CLI-first by philosophy. And it isn't fast. Expect ~1.67s per scan because it's doing AST-level analysis, not regex matching. The closest alternative is Vulture for dead code alone, but Vulture doesn't do secrets, diff review, or AI-defect detection. Skylos's own benchmark claim — 29/29 vs Vulture's 24/29 on a seeded FastAPI + Pydantic repo — is worth attention, though vendor benchmarks deserve scrutiny. The cloud tier is where it gets interesting for teams. Credits don't expire, and scan uploads, PR checks, and the merge gate never burn them — only comparisons, AI fix PRs, triage, MCP remediation, and compliance reports do. For a small team that means the $9 pack can last a long time if you mostly
Researching Skylos? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas Skylos actually fits — and what changes day-one when you adopt it.
Install the CLI with `pip install skylos`, run `skylos . -a` on a Django repo, and review the dead code, secrets, and AI-defect tables grouped by category with confidence scores.
Outcome: Finds hallucinated imports and hardcoded credentials locally with no login or repo connection, before any code leaves the machine.
Add `skylos cicd init` to generate a GitHub Actions workflow, then enable the PR gate after the local scan proves signal on incoming AI-generated contributions.
Outcome: Blocks high-confidence regressions such as removed auth decorators and weakened assertions before merge, with the same dead-code checks that found 29/29 issues on the FastAPI benchmark.
Run `skylos . --trace` in CI so the scanner runs the test suite and records which functions were actually called, then upload results with `skylos . --upload` for shared triage.
Outcome: Dynamic-dispatch false positives drop, and the Cloud Workspace gives the team stored scans, PR comments, Slack alerts, and 90-day trend history across up to 10 projects.
Use Cases
- Run `skylos . -a` on one repo to get a full local audit of dead code, secrets, quality, and AI defects before committing to CI.
- Catch hallucinated imports, phantom calls, and removed auth decorators in AI-generated PRs before they merge.
- Find hardcoded AWS keys and Stripe tokens in source before they reach a public repo.
- Set up `skylos cicd init` to generate a GitHub Actions workflow that blocks high-confidence regressions.
- Use Smart Tracing (`skylos . --trace`) to eliminate dead-code false positives from dynamic dispatch and visitor patterns.
- Upload scan results to the Cloud Workspace for a Flask or Django app that needs shared triage and 90-day trend history.
- Prepare an MCP server for MCP remediations so agent workflows can fix dead code with evidence.
Models Under the Hood
as of 2026-09-25
Limitations
- Skylos requires Python 3.10 or newer and runs on macOS, Linux, or Windows (WSL2 recommended).
- It is a local-first CLI tool that does not require a web browser, though it can generate HTML reports.
- The local CLI is free; cloud upload, LLM review, and CI gates are optional layers, with Cloud Free including 1 project and 10 stored scans, and credit packs ($9 / 50 credits) unlocking the Workspace tier.
as of 2026-09-14
Verification history
We have re-verified Skylos 8 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-checked, vendor evidence unchanged
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-checked, vendor evidence unchanged
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
Showing the 6 most recent of 8 verification passes.
Free to cite with attribution — this page re-verifies continuously.
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published Skylos tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
Local CLI
$0
Cloud Free
$0
Cloud Workspace (Starter pack)
$9 / 50 credits
Enterprise
Custom
Ideal for
Organizations running many repos that need long retention, predictable usage, and audit-ready evidence exports.
What this tier adds
Raises limits to 9,999 projects, 10,000 stored scans, 365-day history, unlimited credits, custom rule scale, and provenance compliance audit export.
Where the pricing makes sense
The company stage and team size where Skylos's pricing actually pencils out — and where peers do it cheaper.
Skylos is priced for solo developers and small Python teams: the OSS CLI is free, the Cloud Workspace is a $9 / 50-credit starter pack, and Enterprise is custom with 9,999 projects and 365-day history. Compared to Semgrep or CodeQL enterprise contracts, Skylos is far cheaper but narrower — you are buying Python-specific AI-code coverage, not a multi-language SAST platform.
Setup time & first value
How long it actually takes to get something useful out of Skylos — broken out by persona, not the marketing-page minute.
Solo developer: about 5 minutes from `pip install skylos` to first findings via `skylos . -a`. Open source maintainer: 15-30 minutes to add `skylos cicd init` and tune thresholds in pyproject.toml. Team lead adding Cloud: add one browser sign-in on first `skylos . --upload`, then configure projects and integrations — the 50 starter credits and 7-day Pro trial activate without a credit card.
Switching to or from Skylos
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From Vulture: replace `vulture .` with `skylos .` for dead code, then add `-a` to also cover secrets, quality, dependencies, and AI defects in one pass.
- →From Bandit: keep Bandit for broad Python security rules or replace it with `skylos . --danger` for SQL injection, command injection, and removed-control detection.
- →From flake8 or pylint: keep style linting and layer `skylos . --quality` on top for complexity, nesting, and duplicate-literal checks with measured-vs-threshold output.
- →From a hosted SAST dashboard: run the free CLI locally first, then upload with `skylos . --upload` once the team needs shared triage and history.
- ↗To Semgrep: point your SAST coverage at Semgrep when you need multi-language rules and keep Skylos for Python AI-defect checks.
- ↗To CodeQL: use CodeQL when your compliance process requires a query-based multi-language analysis platform.
- ↗To Bandit: fall back to Bandit for a pure Python security linter if you do not need dead code, quality, or AI-defect checks.
- ↗To Vulture: keep Vulture if you need the fastest possible single-purpose dead code pass and can accept the lower recall.
Integrations
Resources & Guides
Tutorials & Learning
YouTube returned 6 videos for “Skylos”, and we withheld 6: 6 could not be judged, because “Skylos” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about Skylos.
Official links
Tools that pair well with Skylos
Common stack mates teams adopt alongside Skylos, with the specific reason each pairing earns its keep.
Bito
Bito Governor is an AI model router and code context engine that grounds coding agents in your codebase to cut agent spend 40-70%
Semgrep
AI-assisted SAST, SCA, and secrets scanning that catches real vulnerabilities before they ship.
Cycode
Agentic Development Security Platform that governs AI-written code from IDE prompt to CI/CD runtime.
Featured Head-to-Head Comparisons
Skylos vs Sublime Security
If your pain point is AI-generated Python code introducing bugs or security flaws, Skylos is the clear choice with its low false positives and free tier. If you're defending against advanced email threats like BEC, Sublime Security offers powerful AI detection with custom rules, but its opaque pricing and enterprise focus may not suit small teams. Choose based on attack surface: code vs. inbox.
Skylos vs Push Security
Choose Push Security if you need real-time browser visibility to stop AiTM phishing and control AI tool usage across the enterprise. Choose Skylos if you're a Python developer using AI coding agents and need to catch hallucinated imports and dead code before merge. These tools solve fundamentally different problems—browser security vs. code quality—so your choice depends on whether your pain point is identity-based attacks or AI-generated code defects.
Skylos vs Audioeye
Choose Skylos if you're a Python developer using AI coding agents and need to catch hallucinated imports, dead code, or secrets before PR merge. Choose AudioEye if your priority is web accessibility compliance for ADA/WCAG and you need overlays, VPAT docs, and legal support. They solve nearly opposite problems.
Cognition Ai vs Skylos
Cognition AI is the choice for enterprise teams needing an autonomous engineer to plan, code, and ship complex, multi-step tasks across platforms, backed by financial guarantees and FedRAMP compliance. Skylos is the pick for Python developers who want a lightweight, local-first static analysis tool to catch AI-generated code mistakes and dead code before merge—especially if you use Claude Code or Cursor. Your decision hinges on scope: full autonomous coding vs. pre-merge quality gating.
Marvin vs Skylos
Pick Marvin if you're a Python developer who wants to embed LLM-driven features (chat, classification, extraction) directly into your app with minimal boilerplate. Pick Skylos if you're a Python developer using AI coding assistants and need a tight PR gate that catches dead code, secrets, and AI-specific bugs like hallucinated imports and removed security controls before merge. They solve completely different problems — one builds with LLMs, the other audits what LLMs wrote.
Shipixen vs Skylos
If you're a Python developer using AI coding tools and need to catch hallucinated imports or secrets before merging, Skylos is a must-have (free CLI, low false positives). If you're launching a product and want a polished landing page in minutes without repetitive boilerplate, Shipixen's one-time purchase and AI generation save enormous time. They solve entirely different problems — choose based on whether you need code security or quick front-end shipping.
Alternatives to Skylos
View allFrequently Asked Questions
Used Skylos? Help shape our editorial sentiment research.