CLI tool and library for generating a Software Bill of Materials from container images and filesystems
$ npx skills add anchore/syftAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
$ npx skills add anchore/syftProtect against malicious open source packages 🤖
$ npx skills add safedep/vetScans your project to determine what components you use
$ npx skills add microsoft/component-detectionA vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeGo security checker
$ npx skills add securego/gosecTfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecScan the world (for secrets)
$ npx skills add betterleaks/betterleaksMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
$ npx skills add MobSF/Mobile-Security-Framework-MobSFSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecA powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
$ npx skills add We5ter/Scanners-BoxPerformant type-checking for python.
$ npx skills add facebook/pyre-checkStatic analysis for GitHub Actions
$ npx skills add zizmorcore/zizmorA static analysis security vulnerability scanner for Ruby on Rails applications
$ npx skills add presidentbeef/brakemanVulnerability Static Analysis for Containers
$ npx skills add quay/clairThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
$ npx skills add find-sec-bugs/find-sec-bugsStaticcheck - The advanced Go linter
$ npx skills add dominikh/go-toolsHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep OpenSCA Cli if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.