Alternatives

SootUp alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

SootUp

A new version of Soot with a completely overhauled architecture

86
Quality
86
Trust
795
Stars
#1

Bytecode Viewer

Similarity 133Trust 96Excellent 100

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

16K starsApr 2, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add Konloch/bytecode-viewer
#2

WALA

Similarity 132Trust 88Excellent 87

T.J. Watson Libraries for Analysis, with front ends for Java, Android, and JavaScript, and many common static program analyses.

857 starsJun 14, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add wala/WALA
#3

Tai E

Similarity 129Trust 93Excellent 100

An easy-to-learn/use static analysis framework for Java and Android

1.8K starsJun 9, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add pascal-lab/Tai-e
#4

Recaf

Similarity 123Trust 94Excellent 100

The modern Java bytecode editor

7.2K starsJun 15, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add Col-E/Recaf
#5

NullAway

Similarity 122Trust 96Excellent 100

A tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead

4.1K starsJun 18, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add uber/NullAway
#6

Find Sec Bugs

Similarity 121Trust 94Excellent 99

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

2.4K starsMar 26, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add find-sec-bugs/find-sec-bugs
#7

Jar Analyzer

Similarity 121Trust 94Excellent 100

Jar Analyzer - 一个 JAR 包 GUI 分析工具,内置 AI 助手协助分析,支持 JAR DIFF 分析,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索等

2.1K starsJun 15, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add jar-analyzer/jar-analyzer
#8

Soot

Similarity 121Trust 90Excellent 100

Soot - A Java optimization framework

3.1K starsMay 29, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add soot-oss/soot
#9

Jspecify

Similarity 120Trust 95Excellent 100

An artifact of fully-specified annotations to power static-analysis checks, beginning with nullness analysis.

1.1K starsJun 8, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add jspecify/jspecify
#10

Mastg

Similarity 119Trust 98Excellent 100

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

13K starsJun 18, 2026 pushdevelopmentPythonStatic Analysis
$ npx skills add OWASP/mastg
#11

Sonarqube

Similarity 116Trust 95Excellent 100

Continuous Inspection

11K starsJun 12, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add SonarSource/sonarqube
#12

Checkstyle

Similarity 116Trust 95Excellent 100

Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.

9.0K starsJun 18, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add checkstyle/checkstyle
#13

Booster

Similarity 116Trust 91Excellent 98

🚀Optimizer for mobile applications

5.1K starsMar 15, 2026 pushdevelopmentKotlinStatic Analysis
$ npx skills add didi/booster
#14

Error Prone

Similarity 115Trust 94Excellent 100

Catch common Java mistakes as compile-time errors

7.2K starsJun 17, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add google/error-prone
#15

Spotbugs

Similarity 114Trust 95Excellent 100

SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.

3.9K starsJun 13, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add spotbugs/spotbugs
#16

Pmd

Similarity 114Trust 91Excellent 100

An extensible multilanguage static code analyzer.

5.4K starsJun 12, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add pmd/pmd

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep SootUp if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.