Alternatives

Semgrep Rules alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Semgrep Rules

A collection of my Semgrep rules to facilitate vulnerability research.

86
Quality
87
Trust
827
Stars
#1

Infer

Similarity 127Trust 95Excellent 100

A static analyzer for Java, C, C++, and Objective-C

16K starsJun 13, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add facebook/infer
#2

Cppcheck

Similarity 125Trust 94Excellent 100

static analysis of C/C++ code

6.7K starsJun 18, 2026 pushdevelopmentC++Static Analysis
$ npx skills add cppcheck-opensource/cppcheck
#3

Cake

Similarity 121Trust 81Strong 81

Cake a C23 front end and transpiler written in C

677 starsJun 12, 2026 pushdevelopmentCStatic Analysis
$ npx skills add thradams/cake
#4

Semgrep Rules

Similarity 121Trust 91Excellent 97

Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.

1.2K starsJun 13, 2026 pushdevelopmentHCLStatic Analysis
$ npx skills add semgrep/semgrep-rules
#5

Phasar

Similarity 120Trust 89Excellent 96

A LLVM-based static analysis framework.

1.0K starsJun 11, 2026 pushdevelopmentC++Static Analysis
$ npx skills add secure-software-engineering/phasar
#6

Shellcheck

Similarity 119Trust 92Excellent 100

ShellCheck, a static analysis tool for shell scripts

40K starsJun 11, 2026 pushdevelopmentHaskellStatic Analysis
$ npx skills add koalaman/shellcheck
#7

Semgrep

Similarity 119Trust 97Excellent 100

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

16K starsJun 19, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add semgrep/semgrep
#8

SwiftLint

Similarity 119Trust 93Excellent 100

A tool to enforce Swift style and conventions.

20K starsJun 17, 2026 pushdevelopmentSwiftStatic Analysis
$ npx skills add realm/SwiftLint
#9

Phpstan

Similarity 118Trust 95Excellent 100

PHP Static Analysis Tool - discover bugs in your code without running it!

14K starsJun 18, 2026 pushdevelopmentPHPStatic Analysis
$ npx skills add phpstan/phpstan
#10

PHP CS Fixer

Similarity 118Trust 95Excellent 100

A tool to automatically fix PHP Coding Standards issues

14K starsJun 18, 2026 pushdevelopmentPHPStatic Analysis
$ npx skills add PHP-CS-Fixer/PHP-CS-Fixer
#11

PHP Parser

Similarity 118Trust 92Excellent 100

A PHP parser written in PHP

17K starsFeb 26, 2026 pushdevelopmentPHPStatic Analysis
$ npx skills add nikic/PHP-Parser
#12

Sonarqube

Similarity 118Trust 95Excellent 100

Continuous Inspection

11K starsJun 12, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add SonarSource/sonarqube
#13

Checkstyle

Similarity 118Trust 95Excellent 100

Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.

9.0K starsJun 18, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add checkstyle/checkstyle
#14

Hadolint

Similarity 118Trust 91Excellent 100

Dockerfile linter, validate inline bash, written in Haskell

12K starsJun 11, 2026 pushdevelopmentHaskellStatic Analysis
$ npx skills add hadolint/hadolint
#15

Gosec

Similarity 117Trust 94Excellent 100

Go security checker

8.9K starsJun 15, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add securego/gosec
#16

Error Prone

Similarity 117Trust 94Excellent 100

Catch common Java mistakes as compile-time errors

7.2K starsJun 17, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add google/error-prone

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Semgrep Rules if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.