duriantaco/skylos

High-precision Python SAST & Dead Code Remover. Finds unused functions, secrets, and security flaws with hybrid static analysis + local LLM agents. Privacy-first & low noise. MCP server for SAST too. Docs: https://docs.skylos.dev/

66
/ 100
Established

Supports TypeScript and Go alongside Python with framework-aware analysis for FastAPI, Django, Flask, pytest, Next.js, and React to reduce false positives. Integrates with GitHub Actions for PR gating with inline annotations, VS Code for in-editor findings, and exposes an MCP server for AI agents, while optionally using local LLM agents for verification without requiring cloud infrastructure.

330 stars and 412,112 monthly downloads. Available on PyPI.

Maintenance 13 / 25
Adoption 20 / 25
Maturity 24 / 25
Community 9 / 25

How are scores calculated?

Stars

330

Forks

10

Language

Python

License

Apache-2.0

Last pushed

Mar 11, 2026

Monthly downloads

412,112

Commits (30d)

0

Dependencies

14

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/duriantaco/skylos"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.