Alternatives

Mobsfscan alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Mobsfscan

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

76
Quality
85
Trust
761
Stars
#1

Mastg

Similarity 133Trust 98Excellent 100

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

13K starsJun 15, 2026 pushdevelopmentPythonStatic Analysis
$ npx skills add OWASP/mastg
#2

Jspecify

Similarity 130Trust 96Excellent 100

An artifact of fully-specified annotations to power static-analysis checks, beginning with nullness analysis.

1.1K starsJun 8, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add jspecify/jspecify
#3

Infer

Similarity 127Trust 95Excellent 100

A static analyzer for Java, C, C++, and Objective-C

16K starsJun 13, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add facebook/infer
#4

NullAway

Similarity 124Trust 96Excellent 100

A tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead

4.1K starsJun 15, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add uber/NullAway
#5

Booster

Similarity 123Trust 90Excellent 98

🚀Optimizer for mobile applications

5.1K starsMar 15, 2026 pushdevelopmentKotlinStatic Analysis
$ npx skills add didi/booster
#6

Tai E

Similarity 123Trust 93Excellent 100

An easy-to-learn/use static analysis framework for Java and Android

1.8K starsJun 9, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add pascal-lab/Tai-e
#7

Horusec

Similarity 122Trust 93Excellent 100

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

1.3K starsMay 24, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add ZupIT/horusec
#8

Appshark

Similarity 121Trust 91Excellent 94

Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.

1.7K starsMar 4, 2026 pushdevelopmentKotlinStatic Analysis
$ npx skills add bytedance/appshark
#9

Semgrep

Similarity 119Trust 98Excellent 100

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

16K starsJun 16, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add semgrep/semgrep
#10

Bytecode Viewer

Similarity 119Trust 96Excellent 100

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

16K starsApr 2, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add Konloch/bytecode-viewer
#11

Ast Grep

Similarity 118Trust 93Excellent 100

⚡A CLI tool for code structural search, lint and rewriting. Written in Rust

15K starsJun 15, 2026 pushdevelopmentRustStatic Analysis
$ npx skills add ast-grep/ast-grep
#12

Checkstyle

Similarity 118Trust 97Excellent 100

Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.

8.9K starsJun 16, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add checkstyle/checkstyle
#13

WALA

Similarity 118Trust 89Excellent 87

T.J. Watson Libraries for Analysis, with front ends for Java, Android, and JavaScript, and many common static program analyses.

857 starsJun 14, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add wala/WALA
#14

Sonarqube

Similarity 118Trust 95Excellent 100

Continuous Inspection

11K starsJun 12, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add SonarSource/sonarqube
#15

Recaf

Similarity 117Trust 94Excellent 100

The modern Java bytecode editor

7.2K starsJun 15, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add Col-E/Recaf
#16

Error Prone

Similarity 117Trust 94Excellent 100

Catch common Java mistakes as compile-time errors

7.2K starsJun 15, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add google/error-prone

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Mobsfscan if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.