Alternatives

Clair alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Clair

Vulnerability Static Analysis for Containers

100
Quality
100
Trust
11K
Stars
#1

Grype

Similarity 149Trust 100Excellent 100

A vulnerability scanner for container images and filesystems

12K starsJun 5, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add anchore/grype
#2

Syft

Similarity 148Trust 100Excellent 100

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

9.1K starsJun 8, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add anchore/syft
#3

Kube Linter

Similarity 131Trust 100Excellent 100

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.

3.5K starsJun 4, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add stackrox/kube-linter
#4

Kubesec

Similarity 129Trust 100Excellent 97

Security risk analysis for Kubernetes resources

1.5K starsJun 9, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add controlplaneio/kubesec
#5

Gosec

Similarity 124Trust 100Excellent 100

Go security checker

8.9K starsJun 3, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add securego/gosec
#6

Go Tools

Similarity 124Trust 100Excellent 100

Staticcheck - The advanced Go linter

6.8K starsMay 24, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add dominikh/go-tools
#7

Tfsec

Similarity 124Trust 100Excellent 98

Tfsec is now part of Trivy

7.0K starsMar 25, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add aquasecurity/tfsec
#8

Revive

Similarity 124Trust 100Excellent 100

πŸ”₯ ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint

5.5K starsJun 3, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add mgechev/revive
#9

Nilaway

Similarity 123Trust 100Excellent 100

Static analysis tool to detect potential nil panics in Go code

3.8K starsMay 28, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add uber-go/nilaway
#10

Semgrep

Similarity 119Trust 100Excellent 100

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

15K starsJun 10, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add semgrep/semgrep
#11

Hadolint

Similarity 119Trust 100Excellent 100

Dockerfile linter, validate inline bash, written in Haskell

12K starsJun 1, 2026 pushdevelopmentHaskellStatic Analysis
$ npx skills add hadolint/hadolint
#12

Brakeman

Similarity 118Trust 100Excellent 100

A static analysis security vulnerability scanner for Ruby on Rails applications

7.2K starsJun 5, 2026 pushdevelopmentRubyStatic Analysis
$ npx skills add presidentbeef/brakeman
#13

Go Recipes

Similarity 115Trust 100Excellent 100

🦩 Tools for Go projects

4.5K starsMay 20, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add nikolaydubina/go-recipes
#14

Bearer

Similarity 114Trust 100Excellent 100

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

2.7K starsJun 8, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add Bearer/bearer
#15

ImHex

Similarity 113Trust 100Excellent 100

πŸ” A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

54K starsJun 6, 2026 pushdevelopmentC++Static Analysis
$ npx skills add WerWolv/ImHex
#16

Ruff

Similarity 113Trust 100Excellent 100

An extremely fast Python linter and code formatter, written in Rust.

48K starsJun 6, 2026 pushdevelopmentRustStatic Analysis
$ npx skills add astral-sh/ruff

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Clair if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.