Continuous Inspection
$ npx skills add SonarSource/sonarqubeAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
:coffee: SonarSource Static Analyzer for Java Code Quality and Security
Continuous Inspection
$ npx skills add SonarSource/sonarqubeSonarSource Static Analyzer for JavaScript and TypeScript
$ npx skills add SonarSource/SonarJSCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstylePhan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.
$ npx skills add phan/phanThe modern Java bytecode editor
$ npx skills add Col-E/RecafCatch common Java mistakes as compile-time errors
$ npx skills add google/error-proneA tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead
$ npx skills add uber/NullAwaySpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
$ npx skills add spotbugs/spotbugsHorusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
$ npx skills add ZupIT/horusecAn extensible multilanguage static code analyzer.
$ npx skills add pmd/pmdThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
$ npx skills add find-sec-bugs/find-sec-bugsSoot - A Java optimization framework
$ npx skills add soot-oss/sootAn easy-to-learn/use static analysis framework for Java and Android
$ npx skills add pascal-lab/Tai-e🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
$ npx skills add WerWolv/ImHexAn artifact of fully-specified annotations to power static-analysis checks, beginning with nullness analysis.
$ npx skills add jspecify/jspecifyLightweight static analysis for many languages. Find bug variants with patterns that look like source code.
$ npx skills add semgrep/semgrepHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Sonar Java if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.