SonarQube is a mature code-quality and application-security platform. Its language and analysis matrix spans many programming, markup, and infrastructure languages, with availability and depth varying by product and edition.

Skylos is a smaller, local-first analyzer. It combines dead-code, security, secrets, dependency, quality, and AI-defect checks across several languages. Python has its deepest framework, quality, dead-code, and data-flow coverage; other language analyzers cover narrower subsets. One distinctive check looks for specific security controls removed or weakened in a Git diff, regardless of whether a human or an AI tool authored the change.

This is not a "Skylos is better" comparison. SonarQube is a more mature, more broadly capable platform. But there are specific use cases where Skylos addresses gaps that SonarQube does not cover, and there are teams for whom SonarQube is more than they need. This page is for those teams.


The short version

SonarQubeSkylos
Best forEnterprise governance, multi-language quality gates, portfolio managementPython-focused teams, AI code security, dead code detection
LanguagesBroad, edition-dependent language matrixPython, JavaScript/TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, and C#; targeted Shell and configuration checks
Security scanningYes; broad rule and taint-analysis coverage varies by language and editionYes; Python and JavaScript/TypeScript have the deepest flow analysis, with targeted subsets elsewhere
Dead code detectionSome language rules cover unused or unreachable codeDedicated symbol analysis; deepest and most framework-aware in Python
Code quality metricsYes, including new-code quality gates, coverage, and duplication conditionsYes; complexity, coupling, and cohesion are primarily Python-focused
AI-code governanceAI Code Assurance and AI CodeFixAI-defect checks plus a rule for selected controls removed in Git diffs
Git provenanceSource-control attribution, not model authorship proofHeuristic AI-tool attribution from commit metadata; not model authorship proof
LLM/agent application checksGeneral SAST rules and AI Code Assurance13 static checks mapped to selected OWASP LLM and Agentic categories
Custom rulesQuality profiles, custom rules, and plugins depending on productFocused Python AST rules locally and through Cloud; narrower than SonarQube extensions
IDE integrationSonarQube for IDE across VS Code, IntelliJ, Visual Studio, and EclipsePython-focused VS Code extension
SetupCommunity Build/Server or Cloud plus scanner configurationLocal CLI via pip install skylos; Cloud is optional
CI/CDYes (scanner + server)Yes (auto-generated workflows)
PricingCommunity Build plus paid SonarQube Server and Cloud offeringsOpen-source CLI plus paid Cloud workspace

Where SonarQube is stronger

Language breadth

SonarQube covers a wider set of programming and infrastructure languages than Skylos, including languages Skylos does not analyze, such as C, C++, Ruby, Swift, and Scala. Skylos analyzes Python, JavaScript/TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, and C#, plus targeted Shell and configuration files. Those Skylos checkmarks do not imply equal depth: Python is the most complete analyzer, JavaScript/TypeScript and Go have substantial language-specific coverage, and the remaining languages currently have narrower rule subsets.

Enterprise governance

SonarQube was built for organizations with hundreds of developers and dozens of repositories. It provides:

  • Quality profiles: standardized rule sets across teams
  • Quality gates: pass/fail criteria enforced across the org
  • Portfolio views: aggregate quality metrics across all projects
  • RBAC: role-based access control for different teams
  • Branch analysis: quality tracking across feature branches
  • Pull request decoration: inline comments on PRs

These features matter when you are running a security or quality program at scale. Skylos Cloud now has workspace roles, shared scan history, baseline policies with project inheritance and overrides, exceptions, exports, PR evidence, and organization custom rules. SonarQube remains broader and more mature for portfolio views, permission templates, coverage- and duplication-based gates, and connected-mode IDE governance. See SonarQube's quality-gate model and permission model.

Rule and quality-profile breadth

SonarQube publishes language-specific rules across reliability, security, maintainability, and code-smell categories and lets organizations manage them through quality profiles. Skylos's catalog spans dead code, security, secrets, reliability, quality, AI defects, dependencies, CI/CD, and deployment checks, but category and language depth varies. A raw rule count would not measure equivalent coverage, so compare the rules that apply to your stack.

IDE integration

SonarQube for IDE supports several IDE families and can use connected mode to share server settings. Skylos has a VS Code extension for Python analysis, but it does not yet match SonarQube's IDE breadth or connected-mode policy experience.

Maturity and ecosystem

SonarQube has a long production history, extensive documentation, commercial support, and broad CI/CD and DevOps integrations. Skylos is newer and has a smaller ecosystem.

Quality gate enforcement

SonarQube quality gates can apply conditions to new code, including issue ratings, coverage, duplication, and security-review measures. SonarQube also provides a dedicated AI Code Assurance gate for projects identified as containing AI-generated code. This is a substantially broader quality-gate model than Skylos's finding- and policy-based Cloud gate.


Where Skylos is stronger

Removed-control diff check

Skylos has one explicit diff-oriented check that complements snapshot analysis.

SonarQube analyzes new code and pull requests against a comparison baseline and applies quality gates to the resulting issues. Skylos additionally has a named rule, SKY-L021, that inspects removed and added diff lines for selected security-control regressions.

That rule can detect a change such as:

# Before AI refactoring
@login_required                    # auth decorator
@csrf_protect                      # CSRF protection
@rate_limit("10/minute")           # rate limiting
def transfer_funds(request):
    validate_amount(request.POST["amount"])
    process_transfer(request)

# After refactoring
def transfer_funds(request):       # Skylos flags: auth, CSRF, rate limit REMOVED
    process_transfer(request)

SKY-L021 recognizes selected authentication, validation, logging, permission, rate-limit, CSRF, TLS, cryptography, header, encryption, and sanitization controls. It is a heuristic over Git changes, not a complete proof that a control was required or that AI removed it. SonarQube's new-code analysis may still find a vulnerability in the resulting code; the distinction is that Skylos has an explicit removed-control heuristic.

AI provenance tracking

Skylos can label changed ranges using patterns in Git author names, email addresses, commit subjects, and co-author trailers associated with tools such as Cursor or Copilot. It can then attach that heuristic label to findings on those ranges.

This is useful context but is not proof that a named model generated a specific line. SonarQube offers AI Code Assurance and AI CodeFix, so describing SonarQube as having no AI capability would also be inaccurate.

AI defense scanning

Skylos includes a dedicated defense scanning module for applications that integrate with LLMs:

skylos defend .

It runs the applicable checks from a 13-plugin set, including:

  • Raw input reaching prompt construction without intermediate processing
  • Missing delimiters around user or retrieved RAG context
  • Missing PII filtering on LLM outputs
  • Missing rate limiting and cost controls on LLM API calls
  • Missing logging for LLM interactions

The 13 plugins map to selected categories in the OWASP LLM 2024/2025 and Agentic 2026 taxonomies. Several OWASP categories do not have a matching plugin, so the mapping is not complete Top 10 coverage. SonarQube's published AI features focus on assuring and fixing AI-generated source; teams should compare its current language rules with the LLM-application patterns they need rather than assuming either product covers every AI risk.

Dead code detection

SonarQube detects some dead code patterns — unused imports, unreachable code after return statements, unused local variables. But it is not a dedicated dead code detection tool.

Skylos does full dead code analysis with transitive propagation:

def process_refund(order_id):          # dead — nothing calls this
    validated = _validate_refund(order_id)  # also dead (transitive)
    _send_refund_email(validated)            # also dead (transitive)

Skylos can optionally verify candidate dead-code findings with an LLM. Its deterministic analyzer also propagates reachability through call relationships, so a helper reachable only through a dead caller can be reported in the same analysis. Results still depend on dynamic Python behavior and framework registration; run it on representative code before using findings as a deletion list.

Framework-aware analysis

Skylos has built-in framework visitors for Django, Flask, FastAPI, Pydantic, pytest, Celery, and Click. It understands that @app.route handlers are HTTP entry points, @pytest.fixture functions are called by the test runner, and Pydantic model_validator methods are invoked during validation.

This entry-point modeling primarily reduces dead-code false positives. It is a focused Python feature, not evidence that every security rule understands every framework. SonarQube's framework behavior varies by rule and analyzer version.

Setup and time to first scan

SonarQube Server and Community Build use a server plus scanner configuration; SonarQube Cloud uses a hosted project and scanner workflow. See the official installation overview.

Skylos is a pip package:

pip install skylos
skylos . -a

That is enough for a local scan. Runtime depends on repository size and the checks enabled.

For CI/CD:

skylos cicd init

This generates a GitHub Actions workflow with PR scanning, annotations, review comments, and a quality-gate step. SonarQube also supports pull-request analysis and decoration; its setup varies between Cloud, Server, and the selected CI system.

Distribution and paid features

SonarQube's Community Build, paid Server editions, and Cloud plans have different feature and language matrices. Check the current edition documentation before relying on branch, pull-request, portfolio, or analyzer features.

Skylos's deterministic local analyzers are Apache 2.0 licensed. Its LLM verifier is a Pro feature, and the paid Cloud product adds managed policy, history, collaboration, and trusted pull-request gates. It would be inaccurate to describe every Skylos analysis and governance feature as ungated.

MCP server for AI agents

Skylos includes an MCP (Model Context Protocol) server that provides real-time security scanning inside AI coding agents like Claude Code and Cursor:

python -m skylos_mcp.server

This lets compatible clients invoke Skylos analysis tools. SonarQube now has an official SonarQube MCP Server for SonarQube Server, Cloud, and Community Build, including issue, metric, project, quality-gate, and code-analysis tools. MCP availability is therefore no longer a Skylos-only distinction.


Detection comparison: real examples

SQL injection

SonarQube:

# SonarQube can flag a user-controlled SQL query
query = "SELECT * FROM users WHERE id = " + user_id
cursor.execute(query)

Skylos:

# Skylos flags this (SKY-D211: SQL injection via taint analysis)
user_id = request.args.get("id")
query = f"SELECT * FROM users WHERE id = {user_id}"
cursor.execute(query)

# Skylos does NOT flag this — hardcoded value, not user-controlled
cursor.execute("SELECT * FROM users WHERE active = 1")

Both tools can catch SQL injection. Coverage differs by framework, language, selected SonarQube rules, and the source/sink models each analyzer recognizes.

Hardcoded secrets

SonarQube:

# SonarQube can flag hardcoded-credential patterns
password = "admin123"

Skylos:

# Skylos can flag this with its quality and secrets scanners
API_KEY = "sk-1234567890abcdef"
DATABASE_PASSWORD = "production_password_123"

Both cover hardcoded-credential patterns. Exact provider coverage and validation behavior change over time, so test the credential formats your organization uses.

Explicit security-control removal heuristic

# Skylos can flag these deleted controls in a Git-aware scan

# git diff shows:
# -@login_required
# -@csrf_protect
def admin_panel(request):
    return render(request, "admin.html")

Skylos has an explicit heuristic for these deleted controls. SonarQube instead evaluates the pull request's new code and quality-gate conditions; it may report a resulting issue but does not document the same named removed-control rule.


When to use SonarQube

  • You have a multi-language organization (not just Python)
  • You need enterprise governance: quality profiles, quality gates, portfolio views
  • You need RBAC and compliance features
  • You want broad SonarQube for IDE integration and connected mode
  • You need a proven platform with professional support and SLAs
  • You are running a formal security program across dozens of projects
  • Dedicated call-reachability dead-code analysis is not a priority

When to use Skylos

  • Your codebase is primarily Python, or you have validated Skylos's category depth for your supported languages
  • Your team uses AI coding assistants (Cursor, Copilot, Claude Code) and you want to catch regressions
  • You want dead code detection with transitive propagation and LLM verification
  • You build applications that integrate with LLMs and want Skylos's selected OWASP-mapped static checks
  • You want a local-first tool without server deployment
  • You want security + dead code + quality in a single pip install
  • You want a generated GitHub Actions workflow rather than assembling one manually

When to use both

SonarQube and Skylos do not conflict. A practical setup for teams that use both:

  • SonarQube for enterprise governance, multi-language quality gates, and portfolio-level visibility
  • Skylos for AI regression detection, dead code cleanup, and LLM app security

SonarQube provides broad new-code governance and portfolio-level visibility. Skylos adds focused local analysis and an explicit heuristic for selected controls removed in a Git diff.


Quick start

SonarQube

# Community Edition (self-hosted)
docker run -d --name sonarqube -p 9000:9000 sonarqube:community

# Then: create project, generate token, configure scanner
sonar-scanner \
  -Dsonar.projectKey=my-project \
  -Dsonar.sources=src/ \
  -Dsonar.host.url=http://localhost:9000 \
  -Dsonar.token=your-token

Skylos

pip install skylos
skylos src/ --diff-base origin/main --diff origin/main --danger --quality

Final thoughts

SonarQube is mature and broadly capable. If you need its language matrix, quality profiles, coverage and duplication gates, permission templates, connected IDEs, or portfolio management, it is the stronger fit.

Skylos adds value when Python-heavy teams want dead-code reachability, framework entry-point modeling, security and quality checks, and selected AI-defect and diff-regression checks in one local workflow. Its removed-control rule can catch an auth decorator or rate limiter deleted during refactoring, but it remains a heuristic and is not limited to AI-authored changes.

If your team ships AI-assisted changes, test both tools against the concrete failure modes and governance controls you need. SonarQube and Skylos now both offer AI-oriented capabilities, but they approach them differently.


Try Skylos

If you want Python-focused security, dead code, and AI regression detection without deploying a server:

pip install skylos
skylos src/ --danger --quality

No signup or server is required for a local CLI scan; runtime depends on repository size and enabled checks. View on PyPI | Read the docs



Both tools are open source. SonarQube | Skylos | Skylos Docs | Install Skylos