SonarQube is a mature code-quality and application-security platform. Its language and analysis matrix spans many programming, markup, and infrastructure languages, with availability and depth varying by product and edition.
Skylos is a smaller, local-first analyzer. It combines dead-code, security, secrets, dependency, quality, and AI-defect checks across several languages. Python has its deepest framework, quality, dead-code, and data-flow coverage; other language analyzers cover narrower subsets. One distinctive check looks for specific security controls removed or weakened in a Git diff, regardless of whether a human or an AI tool authored the change.
This is not a "Skylos is better" comparison. SonarQube is a more mature, more broadly capable platform. But there are specific use cases where Skylos addresses gaps that SonarQube does not cover, and there are teams for whom SonarQube is more than they need. This page is for those teams.
The short version
| SonarQube | Skylos | |
|---|---|---|
| Best for | Enterprise governance, multi-language quality gates, portfolio management | Python-focused teams, AI code security, dead code detection |
| Languages | Broad, edition-dependent language matrix | Python, JavaScript/TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, and C#; targeted Shell and configuration checks |
| Security scanning | Yes; broad rule and taint-analysis coverage varies by language and edition | Yes; Python and JavaScript/TypeScript have the deepest flow analysis, with targeted subsets elsewhere |
| Dead code detection | Some language rules cover unused or unreachable code | Dedicated symbol analysis; deepest and most framework-aware in Python |
| Code quality metrics | Yes, including new-code quality gates, coverage, and duplication conditions | Yes; complexity, coupling, and cohesion are primarily Python-focused |
| AI-code governance | AI Code Assurance and AI CodeFix | AI-defect checks plus a rule for selected controls removed in Git diffs |
| Git provenance | Source-control attribution, not model authorship proof | Heuristic AI-tool attribution from commit metadata; not model authorship proof |
| LLM/agent application checks | General SAST rules and AI Code Assurance | 13 static checks mapped to selected OWASP LLM and Agentic categories |
| Custom rules | Quality profiles, custom rules, and plugins depending on product | Focused Python AST rules locally and through Cloud; narrower than SonarQube extensions |
| IDE integration | SonarQube for IDE across VS Code, IntelliJ, Visual Studio, and Eclipse | Python-focused VS Code extension |
| Setup | Community Build/Server or Cloud plus scanner configuration | Local CLI via pip install skylos; Cloud is optional |
| CI/CD | Yes (scanner + server) | Yes (auto-generated workflows) |
| Pricing | Community Build plus paid SonarQube Server and Cloud offerings | Open-source CLI plus paid Cloud workspace |
Where SonarQube is stronger
Language breadth
SonarQube covers a wider set of programming and infrastructure languages than Skylos, including languages Skylos does not analyze, such as C, C++, Ruby, Swift, and Scala. Skylos analyzes Python, JavaScript/TypeScript, Go, Java, Kotlin, PHP, Rust, Dart, and C#, plus targeted Shell and configuration files. Those Skylos checkmarks do not imply equal depth: Python is the most complete analyzer, JavaScript/TypeScript and Go have substantial language-specific coverage, and the remaining languages currently have narrower rule subsets.
Enterprise governance
SonarQube was built for organizations with hundreds of developers and dozens of repositories. It provides:
- Quality profiles: standardized rule sets across teams
- Quality gates: pass/fail criteria enforced across the org
- Portfolio views: aggregate quality metrics across all projects
- RBAC: role-based access control for different teams
- Branch analysis: quality tracking across feature branches
- Pull request decoration: inline comments on PRs
These features matter when you are running a security or quality program at scale. Skylos Cloud now has workspace roles, shared scan history, baseline policies with project inheritance and overrides, exceptions, exports, PR evidence, and organization custom rules. SonarQube remains broader and more mature for portfolio views, permission templates, coverage- and duplication-based gates, and connected-mode IDE governance. See SonarQube's quality-gate model and permission model.
Rule and quality-profile breadth
SonarQube publishes language-specific rules across reliability, security, maintainability, and code-smell categories and lets organizations manage them through quality profiles. Skylos's catalog spans dead code, security, secrets, reliability, quality, AI defects, dependencies, CI/CD, and deployment checks, but category and language depth varies. A raw rule count would not measure equivalent coverage, so compare the rules that apply to your stack.
IDE integration
SonarQube for IDE supports several IDE families and can use connected mode to share server settings. Skylos has a VS Code extension for Python analysis, but it does not yet match SonarQube's IDE breadth or connected-mode policy experience.
Maturity and ecosystem
SonarQube has a long production history, extensive documentation, commercial support, and broad CI/CD and DevOps integrations. Skylos is newer and has a smaller ecosystem.
Quality gate enforcement
SonarQube quality gates can apply conditions to new code, including issue ratings, coverage, duplication, and security-review measures. SonarQube also provides a dedicated AI Code Assurance gate for projects identified as containing AI-generated code. This is a substantially broader quality-gate model than Skylos's finding- and policy-based Cloud gate.
Where Skylos is stronger
Removed-control diff check
Skylos has one explicit diff-oriented check that complements snapshot analysis.
SonarQube analyzes new code and pull requests against a comparison baseline and applies quality gates to the resulting issues. Skylos additionally has a named rule, SKY-L021, that inspects removed and added diff lines for selected security-control regressions.
That rule can detect a change such as:
# Before AI refactoring
@login_required # auth decorator
@csrf_protect # CSRF protection
@rate_limit("10/minute") # rate limiting
def transfer_funds(request):
validate_amount(request.POST["amount"])
process_transfer(request)
# After refactoring
def transfer_funds(request): # Skylos flags: auth, CSRF, rate limit REMOVED
process_transfer(request)
SKY-L021 recognizes selected authentication, validation, logging, permission, rate-limit, CSRF, TLS, cryptography, header, encryption, and sanitization controls. It is a heuristic over Git changes, not a complete proof that a control was required or that AI removed it. SonarQube's new-code analysis may still find a vulnerability in the resulting code; the distinction is that Skylos has an explicit removed-control heuristic.
AI provenance tracking
Skylos can label changed ranges using patterns in Git author names, email addresses, commit subjects, and co-author trailers associated with tools such as Cursor or Copilot. It can then attach that heuristic label to findings on those ranges.
This is useful context but is not proof that a named model generated a specific line. SonarQube offers AI Code Assurance and AI CodeFix, so describing SonarQube as having no AI capability would also be inaccurate.
AI defense scanning
Skylos includes a dedicated defense scanning module for applications that integrate with LLMs:
skylos defend .
It runs the applicable checks from a 13-plugin set, including:
- Raw input reaching prompt construction without intermediate processing
- Missing delimiters around user or retrieved RAG context
- Missing PII filtering on LLM outputs
- Missing rate limiting and cost controls on LLM API calls
- Missing logging for LLM interactions
The 13 plugins map to selected categories in the OWASP LLM 2024/2025 and Agentic 2026 taxonomies. Several OWASP categories do not have a matching plugin, so the mapping is not complete Top 10 coverage. SonarQube's published AI features focus on assuring and fixing AI-generated source; teams should compare its current language rules with the LLM-application patterns they need rather than assuming either product covers every AI risk.
Dead code detection
SonarQube detects some dead code patterns — unused imports, unreachable code after return statements, unused local variables. But it is not a dedicated dead code detection tool.
Skylos does full dead code analysis with transitive propagation:
def process_refund(order_id): # dead — nothing calls this
validated = _validate_refund(order_id) # also dead (transitive)
_send_refund_email(validated) # also dead (transitive)
Skylos can optionally verify candidate dead-code findings with an LLM. Its deterministic analyzer also propagates reachability through call relationships, so a helper reachable only through a dead caller can be reported in the same analysis. Results still depend on dynamic Python behavior and framework registration; run it on representative code before using findings as a deletion list.
Framework-aware analysis
Skylos has built-in framework visitors for Django, Flask, FastAPI, Pydantic, pytest, Celery, and Click. It understands that @app.route handlers are HTTP entry points, @pytest.fixture functions are called by the test runner, and Pydantic model_validator methods are invoked during validation.
This entry-point modeling primarily reduces dead-code false positives. It is a focused Python feature, not evidence that every security rule understands every framework. SonarQube's framework behavior varies by rule and analyzer version.
Setup and time to first scan
SonarQube Server and Community Build use a server plus scanner configuration; SonarQube Cloud uses a hosted project and scanner workflow. See the official installation overview.
Skylos is a pip package:
pip install skylos
skylos . -a
That is enough for a local scan. Runtime depends on repository size and the checks enabled.
For CI/CD:
skylos cicd init
This generates a GitHub Actions workflow with PR scanning, annotations, review comments, and a quality-gate step. SonarQube also supports pull-request analysis and decoration; its setup varies between Cloud, Server, and the selected CI system.
Distribution and paid features
SonarQube's Community Build, paid Server editions, and Cloud plans have different feature and language matrices. Check the current edition documentation before relying on branch, pull-request, portfolio, or analyzer features.
Skylos's deterministic local analyzers are Apache 2.0 licensed. Its LLM verifier is a Pro feature, and the paid Cloud product adds managed policy, history, collaboration, and trusted pull-request gates. It would be inaccurate to describe every Skylos analysis and governance feature as ungated.
MCP server for AI agents
Skylos includes an MCP (Model Context Protocol) server that provides real-time security scanning inside AI coding agents like Claude Code and Cursor:
python -m skylos_mcp.server
This lets compatible clients invoke Skylos analysis tools. SonarQube now has an official SonarQube MCP Server for SonarQube Server, Cloud, and Community Build, including issue, metric, project, quality-gate, and code-analysis tools. MCP availability is therefore no longer a Skylos-only distinction.
Detection comparison: real examples
SQL injection
SonarQube:
# SonarQube can flag a user-controlled SQL query
query = "SELECT * FROM users WHERE id = " + user_id
cursor.execute(query)
Skylos:
# Skylos flags this (SKY-D211: SQL injection via taint analysis)
user_id = request.args.get("id")
query = f"SELECT * FROM users WHERE id = {user_id}"
cursor.execute(query)
# Skylos does NOT flag this — hardcoded value, not user-controlled
cursor.execute("SELECT * FROM users WHERE active = 1")
Both tools can catch SQL injection. Coverage differs by framework, language, selected SonarQube rules, and the source/sink models each analyzer recognizes.
Hardcoded secrets
SonarQube:
# SonarQube can flag hardcoded-credential patterns
password = "admin123"
Skylos:
# Skylos can flag this with its quality and secrets scanners
API_KEY = "sk-1234567890abcdef"
DATABASE_PASSWORD = "production_password_123"
Both cover hardcoded-credential patterns. Exact provider coverage and validation behavior change over time, so test the credential formats your organization uses.
Explicit security-control removal heuristic
# Skylos can flag these deleted controls in a Git-aware scan
# git diff shows:
# -@login_required
# -@csrf_protect
def admin_panel(request):
return render(request, "admin.html")
Skylos has an explicit heuristic for these deleted controls. SonarQube instead evaluates the pull request's new code and quality-gate conditions; it may report a resulting issue but does not document the same named removed-control rule.
When to use SonarQube
- You have a multi-language organization (not just Python)
- You need enterprise governance: quality profiles, quality gates, portfolio views
- You need RBAC and compliance features
- You want broad SonarQube for IDE integration and connected mode
- You need a proven platform with professional support and SLAs
- You are running a formal security program across dozens of projects
- Dedicated call-reachability dead-code analysis is not a priority
When to use Skylos
- Your codebase is primarily Python, or you have validated Skylos's category depth for your supported languages
- Your team uses AI coding assistants (Cursor, Copilot, Claude Code) and you want to catch regressions
- You want dead code detection with transitive propagation and LLM verification
- You build applications that integrate with LLMs and want Skylos's selected OWASP-mapped static checks
- You want a local-first tool without server deployment
- You want security + dead code + quality in a single
pip install - You want a generated GitHub Actions workflow rather than assembling one manually
When to use both
SonarQube and Skylos do not conflict. A practical setup for teams that use both:
- SonarQube for enterprise governance, multi-language quality gates, and portfolio-level visibility
- Skylos for AI regression detection, dead code cleanup, and LLM app security
SonarQube provides broad new-code governance and portfolio-level visibility. Skylos adds focused local analysis and an explicit heuristic for selected controls removed in a Git diff.
Quick start
SonarQube
# Community Edition (self-hosted)
docker run -d --name sonarqube -p 9000:9000 sonarqube:community
# Then: create project, generate token, configure scanner
sonar-scanner \
-Dsonar.projectKey=my-project \
-Dsonar.sources=src/ \
-Dsonar.host.url=http://localhost:9000 \
-Dsonar.token=your-token
Skylos
pip install skylos
skylos src/ --diff-base origin/main --diff origin/main --danger --quality
Final thoughts
SonarQube is mature and broadly capable. If you need its language matrix, quality profiles, coverage and duplication gates, permission templates, connected IDEs, or portfolio management, it is the stronger fit.
Skylos adds value when Python-heavy teams want dead-code reachability, framework entry-point modeling, security and quality checks, and selected AI-defect and diff-regression checks in one local workflow. Its removed-control rule can catch an auth decorator or rate limiter deleted during refactoring, but it remains a heuristic and is not limited to AI-authored changes.
If your team ships AI-assisted changes, test both tools against the concrete failure modes and governance controls you need. SonarQube and Skylos now both offer AI-oriented capabilities, but they approach them differently.
Try Skylos
If you want Python-focused security, dead code, and AI regression detection without deploying a server:
pip install skylos
skylos src/ --danger --quality
No signup or server is required for a local CLI scan; runtime depends on repository size and enabled checks. View on PyPI | Read the docs
Related
- Semgrep vs Skylos
- Bandit vs Skylos
- Snyk vs Skylos
- Deadcode vs Vulture vs Skylos
- Best Python SAST Tools in 2026
- How to Detect Dead Code in Python
- How to Catch Hallucinated Imports in AI Code
Both tools are open source. SonarQube | Skylos | Skylos Docs | Install Skylos