GitHub Code Quality became generally available on 20 July 2026. It runs CodeQL quality queries plus AI-assisted detection on pull requests, suggests fixes with Copilot Autofix, and adds organization dashboards and merge gates. If your code lives on GitHub, it is the obvious default to evaluate.

Skylos is an open-source CLI (Apache-2.0) for dead code, security, secrets and quality checks, plus a "done" check for agent-written changes. It runs locally and in any CI, with an optional Cloud service.

They overlap less than the names suggest. This page covers where each is the better fit and how to use both.

GitHub facts checked on 9 Oct 2026. Pricing and features change; follow the links for the current terms.


The short version

GitHub Code QualitySkylos
What it isGitHub-hosted quality checks: CodeQL queries plus AI-assisted detection, shown in pull requests and org dashboardsOpen-source CLI; optional Skylos Cloud for history, PR checks and team workflow
Where it runsOn GitHub, for GitHub Team and Enterprise Cloud. Not on GitHub Enterprise Server at launchYour machine, any CI runner, the Docker image or the GitHub Action
Price$10 per active committer per month (bots not charged), plus usage-based billing for AI detection and Copilot Autofix, plus Actions compute. Public repos: $0 per committer plus AI usageCLI free (Apache-2.0). Skylos Cloud: Free plan (1 project) and Workspace plan, turned on for good by any one-time credit pack; no seats or subscriptions
SetupTurn it on in GitHub settings, per repository or across the organizationpip install skylos, then skylos cicd init --no-upload for a PR workflow
Python dead codeUnused import, unused local variable, unused global variable, unreachable code, commented-out code. No published query for unused functions, classes or methodsUnused functions, classes, methods, imports and variables across modules, followed transitively, with framework entry points modeled
AIAI-assisted detection and Copilot Autofix (usage-billed; no Copilot subscription needed)A normal scan calls no model. Optional LLM review of dead-code findings with your own model key (skylos agent verify)
Merge gatesRulesets, including coverage thresholds (Cobertura XML), with an evaluate modeExit codes and --gate thresholds in any CI; required checks from the generated workflow
Org viewOrg-level dashboards with maintainability and reliability scoresNone in the CLI. Skylos Cloud keeps scan history and PR checks
Agent-written changesCopilot coding agent runs security and quality analysis on code it createsskylos done checks for deleted, skipped or weakened tests and code that special-cases tests; agent hooks for Claude Code, Codex and Cursor
LanguagesJava, JavaScript, TypeScript, Python, Ruby, C#, GoPython (deepest), TypeScript/JavaScript and Java: dead code, security and quality. PHP, Rust, Dart: dead code and security. Go: dead code and security need the separate skylos-go engine (in the Docker image and GitHub Action, not the PyPI package). C# partial. Kotlin: dead code only. C++: unused file-local functions only. Shell: security only

Sources for the GitHub column: the GA changelog, the feature page and the Python query list. The Copilot coding agent row is from GitHub's 28 Oct 2025 changelog.


Where GitHub Code Quality is the better choice

  • Nothing to install or maintain. You enable it in settings, including across an organization. Skylos needs a workflow file and a pinned version you update.
  • Organization dashboards. GitHub shows maintainability and reliability scores across repositories. The Skylos CLI has no org view.
  • Fixes, not just findings. Copilot Autofix suggests a fix for you to review. A Skylos scan reports; skylos clean can remove unused imports and functions, but there is no general autofix in the CLI.
  • Coverage gates. Rulesets can block a merge on coverage thresholds from Cobertura reports. Skylos has no coverage-percentage gate.
  • AI detection beyond fixed rules. GitHub pairs deterministic CodeQL queries with AI-assisted detection for issues rules miss.
  • Breadth of quality queries. The Python list alone has about a hundred CodeQL queries for reliability and maintainability.

If your team is on GitHub Team or Enterprise Cloud, wants one switch for every repository and is happy with per-committer pricing, start there.


Where Skylos differs

It runs anywhere a CLI runs

Skylos is a Python package and a Docker image. It runs on a laptop before a push, on self-hosted runners, on GitHub Enterprise Server runners, in GitLab CI or anywhere else. GitHub Code Quality isn't available on GitHub Enterprise Server at launch.

The CLI has no per-committer fee

The CLI is free and open source. A team that only needs pull-request checks can run it in CI without a Skylos account:

skylos cicd init --no-upload

This writes a GitHub Actions workflow with a changed-line scan job, PR annotations and comments, and, when it finds a pytest project, a job that runs skylos done. It needs no Skylos account or API key; --no-upload leaves out the Skylos Cloud upload job.

Python dead code across modules

GitHub's published Python queries for Code Quality cover unused imports, unused local and global variables, unreachable code and commented-out code. On 9 Oct 2026 the list had no query for a function, class or method that nothing in the project calls. That is the core Skylos dead-code check:

$ skylos . --format concise
app/main.py:14  SKY-U001  unused function: unused_report
app/report.py:5  SKY-U001  unused function: Report.render_pdf
app/report.py:9  SKY-U004  unused class: OldExporter
app/old_helpers.py:1  SKY-E002  Empty Python file (no code, or docstring-only)

Skylos follows dead code transitively and treats Flask and FastAPI routes, Django views, pytest fixtures and other framework entry points as used. skylos clean . --dry-run previews removing unused imports and functions. See Does Ruff detect dead code? for why per-file checks can't answer this question.

A check for agent-written changes

skylos done --base main re-runs your tests and compares them with the base branch. By default it blocks on failing tests, deleted or skipped tests, loosened test settings, edits to Skylos's own settings, added secrets and code that special-cases the tests. We found no equivalent check in GitHub Code Quality's documentation. Details and limits are on Your AI agent says the tests pass.

Deterministic by default

A normal Skylos scan does not upload source or call a model, so its findings don't depend on a model's output. Dependency CVE checks query OSV and some import checks query package registries; the optional LLM features use a model you choose.


Billing notes

Two points from GitHub's own pages and forum, stated as they appear:

  • Billing for GitHub Code Quality "begins automatically at general availability (July 20, 2026)" (changelog).
  • Two GitHub Community threads ask about charges after Code Quality was turned off: #208611 (23 Sep 2026) and #209596 (6 Oct 2026). The accepted answer in #209596 explains the charge as a prorated licence for the current billing period.

If you trial it, note when the billing period ends.


Using both

They answer different questions, so running both on the same pull request is reasonable:

  • GitHub Code Quality for reliability and maintainability queries, Copilot Autofix and the org dashboard.
  • Skylos for project-wide Python dead code, security and secrets checks you can run locally, and the done check on agent-written changes.

If you want one gate, decide which tool's result is the required status check and let the other comment.



Try Skylos

pip install skylos
skylos . -a

-a turns on the security, secrets, quality, AI-defect and dependency checks; the dependency check queries OSV over the network.