Tfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Tfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecIt's not just a linter that annoys you!
$ npx skills add pylint-dev/pylintInteractive architecture diagrams for codebases
$ npx skills add CodeBoarding/CodeBoardingA tool to enforce Swift style and conventions.
$ npx skills add realm/SwiftLintA vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeProgram for determining types of files for Windows, Linux and MacOS.
$ npx skills add horsicq/Detect-It-EasyBuild, Manage and Deploy AI/ML Systems
$ npx skills add Netflix/metaflowCLI tool and library for generating a Software Bill of Materials from container images and filesystems
$ npx skills add anchore/syftCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstyleStatic code analysis for Kotlin
$ npx skills add detekt/detektA PHP static analysis tool for finding errors and security vulnerabilities in PHP applications
$ npx skills add vimeo/psalmπ₯ ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
$ npx skills add mgechev/reviveAn extensible multilanguage static code analyzer.
$ npx skills add pmd/pmdThe OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
$ npx skills add OWASP/mastgSpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
$ npx skills add spotbugs/spotbugsKubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.
$ npx skills add stackrox/kube-linterHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Checkov if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.