Static analysis for GitHub Actions
$ npx skills add zizmorcore/zizmorAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Protect your secrets using Gitleaks-Action
Static analysis for GitHub Actions
$ npx skills add zizmorcore/zizmorGo security checker
$ npx skills add securego/gosecAn easy-to-learn/use static analysis framework for Java and Android
$ npx skills add pascal-lab/Tai-eSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecNode.js dependency tracing utility
$ npx skills add vercel/nftShellCheck, a static analysis tool for shell scripts
$ npx skills add koalaman/shellcheckA tool to enforce Swift style and conventions.
$ npx skills add realm/SwiftLintA static analyzer for Java, C, C++, and Objective-C
$ npx skills add facebook/inferPHP Static Analysis Tool - discover bugs in your code without running it!
$ npx skills add phpstan/phpstanA tool to automatically fix PHP Coding Standards issues
$ npx skills add PHP-CS-Fixer/PHP-CS-FixerA PHP parser written in PHP
$ npx skills add nikic/PHP-ParserContinuous Inspection
$ npx skills add SonarSource/sonarqubeCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstyleDockerfile linter, validate inline bash, written in Haskell
$ npx skills add hadolint/hadolintMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
$ npx skills add MobSF/Mobile-Security-Framework-MobSFCatch common Java mistakes as compile-time errors
$ npx skills add google/error-proneHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Gitleaks Action if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.