A vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Detect non-inclusive language in your source code.
A vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeGo security checker
$ npx skills add securego/gosecCLI tool and library for generating a Software Bill of Materials from container images and filesystems
$ npx skills add anchore/syft🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
$ npx skills add mgechev/reviveTfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecHorusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
$ npx skills add ZupIT/horusec🐶 Automated code review tool integrated with any code analysis tools regardless of programming language
$ npx skills add reviewdog/reviewdogVulnerability Static Analysis for Containers
$ npx skills add quay/clairA Golang tool that does static analysis, unit testing, code review and generate code quality report.
$ npx skills add qax-os/goreporterStaticcheck - The advanced Go linter
$ npx skills add dominikh/go-toolsKubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.
$ npx skills add stackrox/kube-linterStatic analysis tool to detect potential nil panics in Go code
$ npx skills add uber-go/nilawayprealloc is a Go static analysis tool to find slice declarations that could potentially be preallocated.
$ npx skills add alexkohler/preallocProtect against malicious open source packages 🤖
$ npx skills add safedep/vetAn Intelligent Python Code Quality Analyzer
$ npx skills add ludo-technologies/pyscnSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Woke if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.