A static analyzer for Java, C, C++, and Objective-C
$ npx skills add facebook/inferAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
A static analyzer for Java, C, C++, and Objective-C
$ npx skills add facebook/inferPerformant type-checking for python.
$ npx skills add facebook/pyre-checkSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecAn extremely fast Python linter and code formatter, written in Rust.
$ npx skills add astral-sh/ruffA vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeVulnerability Static Analysis for Containers
$ npx skills add quay/clairContinuous Inspection
$ npx skills add SonarSource/sonarqubeCLI tool and library for generating a Software Bill of Materials from container images and filesystems
$ npx skills add anchore/syftCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstyleGo security checker
$ npx skills add securego/gosecA static analysis security vulnerability scanner for Ruby on Rails applications
$ npx skills add presidentbeef/brakemanThe modern Java bytecode editor
$ npx skills add Col-E/RecafCatch common Java mistakes as compile-time errors
$ npx skills add google/error-proneStaticcheck - The advanced Go linter
$ npx skills add dominikh/go-toolsValidate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.
$ npx skills add sverweij/dependency-cruiserstatic analysis of C/C++ code
$ npx skills add cppcheck-opensource/cppcheckHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Semgrep if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.