VS Code Extension

Move off deprecated
`python.linting` without losing coverage

Skylos adds Python static analysis and security checks in VS Code for teams that already use Ruff, Pylint, or Mypy. Catch dead code, secrets, risky patterns, and AI-generated mistakes without relying on the old `python.linting.*` settings.

Free & open source · Works with Python · AI Assist is off by default · Cloud providers require your API key

Save
Static scan trigger
1s
Default AI idle delay
60s
Cache duration
3
AI provider modes
VS Code Migration

`python.linting` is deprecated in VS Code

VS Code now pushes Python teams toward dedicated tool extensions instead of the old `python.linting.*` settings. Skylos fits that newer workflow as a Python static-analysis and security layer that complements Ruff, Pylint, and Mypy rather than replacing them.

Skylos in VS Code
Skylos VS Code Extension
Features

Everything you need to ship safer code

Local static checks on save, with a separate optional AI pass after you pause editing.

On-save static analysis
Saving a Python file runs the local Skylos CLI and refreshes dead-code, secret, and security diagnostics.
Inline Diagnostics
Issues appear inline with severity and context. Review findings without leaving your editor.
Optional AI Verification
After you pause while editing, AI Assist can send the changed function to OpenAI, Anthropic, or a local OpenAI-compatible server you configure.
Smart Caching
Only re-analyzes functions that actually changed. Fast, efficient, and won't burn your API credits.
Streaming Responses
See fix progress in real-time as the AI generates code. No more waiting for spinners.
Secrets & Danger Scanning
Detects hardcoded API keys, eval/exec calls, unsafe pickle loads, and more.
How it works

One predictable editor workflow

Save to run deterministic local checks. If you enable AI Assist, editing starts a separate idle timer and only the changed function is sent to your configured provider.

1
Static checks — on save
Detects dead code, unused imports, unreachable functions
Scans for hardcoded secrets and API keys
Flags dangerous patterns (eval, pickle, shell=True)
Runs locally and makes no provider call
2
Optional AI Assist — after idle
Analyzes changed functions after 1s of idle by default
Catches logic errors, type bugs, undefined variables
One-click fix with diff preview
Uses your chosen cloud-provider key, or a local OpenAI-compatible server
Data flow

What stays local—and what leaves your editor

Static checks

File content is analyzed by the local Skylos CLI. This path does not send source code to Skylos Cloud or an AI provider.

OpenAI or Anthropic

When AI Assist is enabled, changed function code and the analysis prompt go directly from the extension to the provider you selected. That provider's terms and retention policy apply.

Local AI server

Choose the local provider mode to send the same AI request to an OpenAI-compatible endpoint you control. Skylos Cloud is not in either AI request path.

Quick Setup

Up and running in 2 minutes

1
Install the extension
Search "Skylos" in VS Code marketplace or click the install button above.
2
Install Skylos CLI
pip install skylos
3
Choose AI Assist (optional)
Add an OpenAI or Anthropic key, or choose a local OpenAI-compatible server. Skip this step to use local static checks only.
Extension Settings
Customize Skylos to fit your workflow
skylos.aiProvider
Choose the optional AI Assist backend
"openai" | "anthropic" | "local"
skylos.openaiApiKey
Your OpenAI API key
string
skylos.anthropicApiKey
Your Anthropic API key
string
skylos.localBaseUrl
Your local OpenAI-compatible endpoint
URL
skylos.enableRealtimeAI
Opt in to automatic AI Assist while editing
false
skylos.idleMs
Wait time before optional AI analysis (ms)
1000
skylos.enableSecrets
Scan for hardcoded secrets
true
skylos.enableDanger
Flag dangerous code patterns
true

Stop bugs before they ship

Use the local scanner on save, then opt in to a cloud or local AI provider only if you want the additional AI Assist pass.