A vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Protect against malicious open source packages 🤖
A vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeGo security checker
$ npx skills add securego/gosecCLI tool and library for generating a Software Bill of Materials from container images and filesystems
$ npx skills add anchore/syft🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
$ npx skills add mgechev/reviveHorusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
$ npx skills add ZupIT/horusecSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecOpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
$ npx skills add XmirrorSecurity/OpenSCA-cliThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
$ npx skills add find-sec-bugs/find-sec-bugsInteractive architecture diagrams for codebases
$ npx skills add CodeBoarding/CodeBoardingTfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecKubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.
$ npx skills add stackrox/kube-linterScan the world (for secrets)
$ npx skills add betterleaks/betterleaksMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
$ npx skills add MobSF/Mobile-Security-Framework-MobSFA tool to enforce Swift style and conventions.
$ npx skills add realm/SwiftLintProgram for determining types of files for Windows, Linux and MacOS.
$ npx skills add horsicq/Detect-It-EasyCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstyleHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Vet if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.