Alternatives

Security Code Scan alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Security Code Scan

Vulnerability Patterns Detector for C# and VB.NET

56
Quality
77
Trust
975
Stars
#1

Meziantou.Analyzer

Similarity 136Trust 94Excellent 100

A powerful C# Roslyn analyzer that uses static analysis to detect bugs, surface security issues, and enforce best practices—helping developers and AI write more reliable code.

1.1K starsJun 14, 2026 pushdevelopmentC#Static Analysis
$ npx skills add meziantou/Meziantou.Analyzer
#2

Phan

Similarity 124Trust 91Excellent 98

Phan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.

5.6K starsMay 12, 2026 pushdevelopmentPHPStatic Analysis
$ npx skills add phan/phan
#3

Cpp2IL

Similarity 121Trust 93Excellent 100

Work-in-progress tool to reverse unity's IL2CPP toolchain.

2.4K starsJun 10, 2026 pushdevelopmentC#Static Analysis
$ npx skills add SamboyCoding/Cpp2IL
#4

Sonar Java

Similarity 121Trust 89Excellent 97

:coffee: SonarSource Static Analyzer for Java Code Quality and Security

1.2K starsJun 12, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add SonarSource/sonar-java
#5

ImHex

Similarity 120Trust 98Excellent 100

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

54K starsJun 12, 2026 pushdevelopmentC++Static Analysis
$ npx skills add WerWolv/ImHex
#6

Detekt

Similarity 117Trust 94Excellent 100

Static code analysis for Kotlin

7.0K starsJun 14, 2026 pushdevelopmentKotlinStatic Analysis
$ npx skills add detekt/detekt
#7

Binsider

Similarity 116Trust 92Excellent 100

Analyze ELF binaries like a boss 😼🕵️‍♂️

4.3K starsJun 14, 2026 pushdevelopmentRustStatic Analysis
$ npx skills add orhun/binsider
#8

Codechecker

Similarity 115Trust 93Excellent 100

CodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools.

2.6K starsJun 11, 2026 pushdevelopmentPythonStatic Analysis
$ npx skills add Ericsson/codechecker
#9

Find Sec Bugs

Similarity 115Trust 94Excellent 99

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

2.4K starsMar 26, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add find-sec-bugs/find-sec-bugs
#10

Sonar Dotnet

Similarity 114Trust 82Strong 82

Code analyzer for C# and VB.NET projects

910 starsJun 13, 2026 pushdevelopmentC#Static Analysis
$ npx skills add SonarSource/sonar-dotnet
#11

Horusec

Similarity 114Trust 92Excellent 100

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

1.3K starsMay 24, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add ZupIT/horusec
#12

ApplicationInspector

Similarity 114Trust 92Excellent 98

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.

4.4K starsFeb 17, 2026 pushdevelopmentC#Static Analysis
$ npx skills add microsoft/ApplicationInspector
#13

Ruff

Similarity 112Trust 95Excellent 100

An extremely fast Python linter and code formatter, written in Rust.

48K starsJun 14, 2026 pushdevelopmentRustStatic Analysis
$ npx skills add astral-sh/ruff
#14

Shellcheck

Similarity 111Trust 92Excellent 100

ShellCheck, a static analysis tool for shell scripts

40K starsJun 11, 2026 pushdevelopmentHaskellStatic Analysis
$ npx skills add koalaman/shellcheck
#15

Mobile Security Framework MobSF

Similarity 111Trust 96Excellent 100

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

21K starsMay 19, 2026 pushdevelopmentJavaScriptStatic Analysis
$ npx skills add MobSF/Mobile-Security-Framework-MobSF
#16

Semgrep

Similarity 111Trust 97Excellent 100

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

16K starsJun 18, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add semgrep/semgrep

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Security Code Scan if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.