Removed security controls
Auth decorators, CSRF checks, rate limits, and other controls removed by refactors.
Run Skylos locally for free to catch dead code, secrets, risky AI changes, and technical-debt hotspots. Add Cloud when your team needs history, PR evidence, and shared triage.
No login for local scans. Try skylos . -a on one repo first.
Representative results from simplified browser checks. The full Skylos scanner runs locally with repository context and 200+ rules.
What it catches
Security and reliability mistakes that slip through busy AI-assisted reviews.
Auth decorators, CSRF checks, rate limits, and other controls removed by refactors.
Invented imports and APIs, impossible dependency versions, missing guards, and insecure defaults.
Lower-noise checks for Django, Flask, FastAPI, Pydantic, and pytest.
Find hardcoded credentials, injection paths, unsafe calls, and dependency risks.
Evidence
Follow the links to the exact upstream pull requests and maintainer decisions.
Rollout path
Add CI only after the local scan finds useful signal.
No login or repo connection.
Check a repo you already care about.
Block risky merges after Skylos earns trust.
Pricing
Free is for local signal. Cloud is for team memory. Enterprise is for scale, retention, and audit evidence.
For one developer or one repo proving whether Skylos catches useful signal.
For teams that need shared history, review workflow, and evidence across repos.
50 scan uploads, 25 comparisons, 16 PR auto-fix actions, 10 AI triage actions, or 5 MCP remediations.
For teams that need predictable usage, longer retention, and compliance-friendly audit exports.
Evaluate Skylos
Follow the quickstart, review how Skylos handles security, or compare it with your current scanner.
Install Skylos and run the first local scan on your repository.
Open quickstartReview data handling, service controls, retention, and operational status.
Review trust detailsCompare workflows, detection scope, and tradeoffs before changing a quality gate.
Compare scannersCommon questions
Yes. The CLI runs locally without login. Cloud is paid for shared history, scan comparison, PR evidence, collaboration, and governance.
A standard local CLI scan stays on your machine and needs no account. If you choose Cloud, a report may include findings, file paths, line numbers, and optional snippets. Dependency lookups and configured AI providers are also explicit networked features.
Static analysis covers Python, JavaScript and TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment configuration. Analysis depth varies by language; deterministic local API verification currently covers Python, JavaScript and TypeScript, Go, and Java.
Cloud adds uploaded scan history, run comparison, shared triage, exceptions, exports, Slack or Discord alerts, PR workflows, and cloud AI actions.
Skylos can run beside an existing scanner and focus on AI-heavy repositories, removed controls, framework-aware dead code, technical debt, and changed-code regressions.
Yes. Run Skylos before commit or in CI to catch removed validation, auth checks, rate limits, secrets handling, and other risky AI changes.
Add Cloud when reviewers need history, evidence, and shared triage.