A vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
A vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeVulnerability Static Analysis for Containers
$ npx skills add quay/clairπ₯ ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
$ npx skills add mgechev/reviveGo security checker
$ npx skills add securego/gosecKubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.
$ npx skills add stackrox/kube-linterSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecStaticcheck - The advanced Go linter
$ npx skills add dominikh/go-toolsInteractive architecture diagrams for codebases
$ npx skills add CodeBoarding/CodeBoardingTfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecStatic analysis tool to detect potential nil panics in Go code
$ npx skills add uber-go/nilawayA tool to enforce Swift style and conventions.
$ npx skills add realm/SwiftLintLightweight static analysis for many languages. Find bug variants with patterns that look like source code.
$ npx skills add semgrep/semgrepDockerfile linter, validate inline bash, written in Haskell
$ npx skills add hadolint/hadolintProgram for determining types of files for Windows, Linux and MacOS.
$ npx skills add horsicq/Detect-It-EasyCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstylePrevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
$ npx skills add bridgecrewio/checkovHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Syft if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.