Alternatives

Horusec alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

100
Quality
92
Trust
1.3K
Stars
#1

Detekt

Similarity 133Trust 94Excellent 100

Static code analysis for Kotlin

7.0K starsJun 19, 2026 pushdevelopmentKotlinStatic Analysis
$ npx skills add detekt/detekt
#2

Grype

Similarity 132Trust 94Excellent 100

A vulnerability scanner for container images and filesystems

12K starsJun 12, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add anchore/grype
#3

Syft

Similarity 131Trust 91Excellent 100

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

9.1K starsJun 18, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add anchore/syft
#4

Revive

Similarity 131Trust 96Excellent 100

🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint

5.5K starsJun 11, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add mgechev/revive
#5

Vet

Similarity 127Trust 92Excellent 100

Protect against malicious open source packages 🤖

1.1K starsJun 11, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add safedep/vet
#6

Checkstyle

Similarity 126Trust 95Excellent 100

Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.

9.0K starsJun 18, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add checkstyle/checkstyle
#7

Spotbugs

Similarity 124Trust 95Excellent 100

SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.

3.9K starsJun 13, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add spotbugs/spotbugs
#8

Pmd

Similarity 124Trust 91Excellent 100

An extensible multilanguage static code analyzer.

5.4K starsJun 12, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add pmd/pmd
#9

Gosec

Similarity 123Trust 94Excellent 100

Go security checker

8.9K starsJun 15, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add securego/gosec
#10

Find Sec Bugs

Similarity 123Trust 94Excellent 99

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

2.4K starsMar 26, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add find-sec-bugs/find-sec-bugs
#11

CodeBoarding

Similarity 123Trust 92Excellent 100

Interactive architecture diagrams for codebases

2.3K starsJun 19, 2026 pushdevelopmentPythonStatic Analysis
$ npx skills add CodeBoarding/CodeBoarding
#12

Tfsec

Similarity 123Trust 92Excellent 100

Tfsec is now part of Trivy

7.0K starsMar 25, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add aquasecurity/tfsec
#13

Jspecify

Similarity 122Trust 95Excellent 100

An artifact of fully-specified annotations to power static-analysis checks, beginning with nullness analysis.

1.1K starsJun 8, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add jspecify/jspecify
#14

Kube Linter

Similarity 122Trust 95Excellent 100

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.

3.5K starsJun 10, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add stackrox/kube-linter
#15

Sonar Java

Similarity 121Trust 89Excellent 97

:coffee: SonarSource Static Analyzer for Java Code Quality and Security

1.2K starsJun 12, 2026 pushdevelopmentJavaStatic Analysis
$ npx skills add SonarSource/sonar-java
#16

Kubesec

Similarity 119Trust 90Excellent 97

Security risk analysis for Kubernetes resources

1.5K starsJun 15, 2026 pushdevelopmentGoStatic Analysis
$ npx skills add controlplaneio/kubesec

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Horusec if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.