Skylos

by duriantaco

630 downloads Not rated yet
GitHub

About

Dead code detection, security scanning, and code quality analysis for Python, TypeScript, and Go. 98% recall with 3x fewer false positives than Vulture. 5 tools: analyze, security_scan, quality_check, secrets_scan, remediate. AI-powered auto-fix agent.

Explore

- Real-time Analysis: Detects bugs as you type — no save required
- CodeLens Buttons: "Fix with AI" and "Dismiss" appear inline on error lines
- Streaming Fixes: See fix progress in real-time
- Smart Caching: Only re-analyzes functions that actually changed
- Multi-Provider: Choose between OpenAI and Anthropic

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Skylos
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

| Objective | Command | Outcome |
| :--- | :--- | :--- |
| Hunt Dead Code | skylos . | Prune unreachable functions and unused imports |
| Precise Hunt | skylos . --trace | Cross-reference with runtime data |
| Audit Risk & Quality | skylos . --secrets --danger --quality | Security leaks, taint tracking, code rot |
| Detect Unused Pytest Fixtures | skylos . --pytest-fixtures | Find unused @pytest.fixture across tests + conftest |
| AI-Powered Analysis | skylos agent analyze . --model gpt-4.1 | Hybrid static + LLM analysis with project context |
| AI Audit | skylos agent security-audit . | Deep LLM review with interactive file selection |
| Auto-Remediate | skylos agent remediate . --auto-pr | Scan, fix, test, and open a PR — end to end |
| PR Review | skylos agent review | Analyze only git-changed files |
| PR Review (JSON) | skylos agent review . --model claude-sonnet-4-20250514 --format json -o results.json | LLM review with code-level fix suggestions |
| Local LLM | skylos agent analyze . --base-url http://localhost:11434/v1 --model codellama | Use Ollama/LM Studio (no API key needed) |
| Secure the Gate | skylos --gate | Block risky code from merging |
| Whitelist | skylos whitelist 'handle_*' | Suppress known dynamic patterns |
| 🚀 Setup CI/CD | skylos cicd init | Generate GitHub Actions workflow in 30 seconds |
| CI/CD + Upload | skylos cicd init --upload | Generate workflow with cloud dashboard upload |
| Diff Filtering | skylos . --diff origin/main | Only show findings in changed lines |
| Quality Gate (CI) | skylos cicd gate -i results.json | Fail builds when issues found |
| PR Review (CI) | skylos cicd review -i results.json | Post inline comments on PRs |


Skylos supports cloud and local LLM providers:

bash

Skylos can use API keys from (1) skylos key, or (2) environment variables.

Set defaults to avoid repeating flags:


bash

curl -fsSL https://ollama.com/install.sh | sh


Once configured, you can ask Claude:

- "Scan my project for security issues" → calls security_scan
- "Check code quality in src/" → calls quality_check
- "Find hardcoded secrets" → calls secrets_scan
- "Fix security issues in my project" → calls remediate

bash
skylos init

Creates [tool.skylos] in your pyproject.toml:
toml
[tool.skylos]

pip install skylos
skylos sync setup

1. Dashboard -> Settings -> Install GitHub App
2. Select your repository
3. In GitHub repo settings:
- Settings -> Branches -> Add rule -> main
- Require status checks
- Select "Skylos Quality Gate"

| Environment | Tool | Use Case |
|-------------|------|----------|
| VS Code | Skylos Extension | Real-time guarding. Highlights code rot and risks on-save. |
| Web UI | skylos run | Launch a local dashboard at localhost:5090 for visual auditing. |
| CI/CD | GitHub Actions / Pre-commit | Automated gates that audit every PR before it merges. |
| Quality Gate | skylos --gate | Block deployment if security or complexity thresholds are exceeded. |

Suppress false positives permanently without inline comments cluttering your code.

``toml
[tool.skylos.whitelist]

curl http://localhost:11434/v1/models

1. Fork the repository
2. Create a feature branch (
git checkout -b feature/amazing-feature)
3. Commit your changes (
git commit -m 'Add amazing feature')
4. Push to the branch (
git push origin feature/amazing-feature`)
5. Open a Pull Request

analyze

Dead code detection (unused functions, imports, classes, variables)

security_scan

Security vulnerability scan (`--danger` equivalent)

quality_check

Code quality and complexity analysis (`--quality` equivalent)

secrets_scan

Hardcoded secrets detection (`--secrets` equivalent)

remediate

End-to-end: scan, generate LLM fixes, validate with tests

| Tool | Description |
|------|-------------|
| analyze | Dead code detection (unused functions, imports, classes, variables) |
| security_scan | Security vulnerability scan (--danger equivalent) |
| quality_check | Code quality and complexity analysis (--quality equivalent) |
| secrets_scan | Hardcoded secrets detection (--secrets equivalent) |
| remediate | End-to-end: scan, generate LLM fixes, validate with tests |

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "skylos": {
            "skylos": {
                "command": "python3",
                "args": [
                    "-m",
                    "skylos_mcp.server"
                ]
            }
        }
    }
}

McpServers

{
    "skylos": {
        "command": "python3",
        "args": [
            "-m",
            "skylos_mcp.server"
        ]
    }
}

What is Skylos?

> Skylos is a privacy-first SAST tool for Python, TypeScript, and Go that bridges the gap between traditional static analysis and AI agents. It detects dead code, security vulnerabilities (SQLi, SSRF, Secrets), and code quality issues with high precision.

Unlike standard linters (like Vulture or Bandit) that struggle with dynamic Python patterns, Skylos uses a hybrid engine (AST + optional Local/Cloud LLM). This allows it to:

1. Eliminate False Positives: Distinguishes between truly dead code and framework magic (e.g., pytest.fixture, FastAPI routes).
2. Verify via Runtime: Optional --trace mode validates findings against actual runtime execution.
3. Find Logic Bugs: Goes beyond linting to find deep logic errors that regex-based tools miss.

---

🚀 New to Skylos? Start with CI/CD Integration

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.