Alternatives

Cfn Nag alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Cfn Nag

Linting tool for CloudFormation templates

72
Quality
84
Trust
1.3K
Stars
#1

Checkov

Similarity 134Trust 95Excellent 100

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

8.8K starsJun 14, 2026 pushdevelopmentPythonStatic Analysis
$ npx skills add bridgecrewio/checkov
#2

Tfsec

Similarity 125Trust 92Excellent 100

Tfsec is now part of Trivy

7.0K starsMar 25, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add aquasecurity/tfsec
#3

Brakeman

Similarity 114Trust 90Excellent 100

A static analysis security vulnerability scanner for Ruby on Rails applications

7.2K starsJun 15, 2026 pushdevelopmentRubyStatic Analysis
$ npx skills add presidentbeef/brakeman
#4

Reek

Similarity 114Trust 93Excellent 100

Code smell detector for Ruby

4.1K starsJun 12, 2026 pushdevelopmentRubyStatic Analysis
$ npx skills add troessner/reek
#5

Rubycritic

Similarity 114Trust 92Excellent 100

A Ruby code quality reporter

3.5K starsJun 18, 2026 pushdevelopmentRubyStatic Analysis
$ npx skills add whitesmith/rubycritic
#6

Appshark

Similarity 113Trust 91Excellent 94

Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.

1.7K starsMar 4, 2026 pushdevelopmentKotlinStatic Analysis
$ npx skills add bytedance/appshark
#7

I18n Tasks

Similarity 113Trust 93Excellent 100

Manage translation and localization with static analysis, for Ruby i18n

2.2K starsMay 30, 2026 pushdevelopmentRubyStatic Analysis
$ npx skills add glebm/i18n-tasks
#8

ImHex

Similarity 112Trust 98Excellent 100

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

54K starsJun 12, 2026 pushdevelopmentC++Static Analysis
$ npx skills add WerWolv/ImHex
#9

Ruff

Similarity 112Trust 95Excellent 100

An extremely fast Python linter and code formatter, written in Rust.

48K starsJun 14, 2026 pushdevelopmentRustStatic Analysis
$ npx skills add astral-sh/ruff
#10

Shellcheck

Similarity 111Trust 92Excellent 100

ShellCheck, a static analysis tool for shell scripts

40K starsJun 11, 2026 pushdevelopmentHaskellStatic Analysis
$ npx skills add koalaman/shellcheck
#11

Mobile Security Framework MobSF

Similarity 111Trust 96Excellent 100

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

21K starsMay 19, 2026 pushdevelopmentJavaScriptStatic Analysis
$ npx skills add MobSF/Mobile-Security-Framework-MobSF
#12

Semgrep

Similarity 111Trust 97Excellent 100

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

16K starsJun 19, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add semgrep/semgrep
#13

Mastg

Similarity 111Trust 98Excellent 100

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

13K starsJun 18, 2026 pushdevelopmentPythonStatic Analysis
$ npx skills add OWASP/mastg
#14

Bytecode Viewer

Similarity 111Trust 96Excellent 100

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

16K starsApr 2, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add Konloch/bytecode-viewer
#15

SwiftLint

Similarity 111Trust 93Excellent 100

A tool to enforce Swift style and conventions.

20K starsJun 17, 2026 pushdevelopmentSwiftStatic Analysis
$ npx skills add realm/SwiftLint
#16

Infer

Similarity 111Trust 95Excellent 100

A static analyzer for Java, C, C++, and Objective-C

16K starsJun 13, 2026 pushdevelopmentOCamlStatic Analysis
$ npx skills add facebook/infer

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Cfn Nag if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.