Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
$ npx skills add bridgecrewio/checkovAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Linting tool for CloudFormation templates
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
$ npx skills add bridgecrewio/checkovTfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecA static analysis security vulnerability scanner for Ruby on Rails applications
$ npx skills add presidentbeef/brakemanCode smell detector for Ruby
$ npx skills add troessner/reekA Ruby code quality reporter
$ npx skills add whitesmith/rubycriticAppshark is a static taint analysis platform to scan vulnerabilities in an Android app.
$ npx skills add bytedance/appsharkManage translation and localization with static analysis, for Ruby i18n
$ npx skills add glebm/i18n-tasks🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
$ npx skills add WerWolv/ImHexAn extremely fast Python linter and code formatter, written in Rust.
$ npx skills add astral-sh/ruffShellCheck, a static analysis tool for shell scripts
$ npx skills add koalaman/shellcheckMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
$ npx skills add MobSF/Mobile-Security-Framework-MobSFLightweight static analysis for many languages. Find bug variants with patterns that look like source code.
$ npx skills add semgrep/semgrepThe OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
$ npx skills add OWASP/mastgA Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
$ npx skills add Konloch/bytecode-viewerA tool to enforce Swift style and conventions.
$ npx skills add realm/SwiftLintA static analyzer for Java, C, C++, and Objective-C
$ npx skills add facebook/inferHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Cfn Nag if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.