SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
$ npx skills add spotbugs/spotbugsAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
$ npx skills add spotbugs/spotbugsAn extensible multilanguage static code analyzer.
$ npx skills add pmd/pmdCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstyleThe modern Java bytecode editor
$ npx skills add Col-E/RecafSoot - A Java optimization framework
$ npx skills add soot-oss/sootAn easy-to-learn/use static analysis framework for Java and Android
$ npx skills add pascal-lab/Tai-eSpoon is a metaprogramming library to analyze and transform Java source code. :spoon: is made with :heart:, :beers: and :sparkles:. It parses source files to build a well-designed AST with powerful analysis and transformation API.
$ npx skills add INRIA/spoonPySonar2: a semantic indexer for Python with interprocedual type inference
$ npx skills add yinwang0/pysonar2A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
$ npx skills add Konloch/bytecode-viewerContinuous Inspection
$ npx skills add SonarSource/sonarqubeCatch common Java mistakes as compile-time errors
$ npx skills add google/error-proneA tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead
$ npx skills add uber/NullAwayHorusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
$ npx skills add ZupIT/horusecProtect against malicious open source packages 🤖
$ npx skills add safedep/vetSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecJar Analyzer - 一个 JAR 包 GUI 分析工具,内置 AI 助手协助分析,支持 JAR DIFF 分析,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索等
$ npx skills add jar-analyzer/jar-analyzerHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Find Sec Bugs if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.