Dead code, security, secrets detection and code quality for Python, TypeScript, Go.
Open-source, local-first checks for dead code, security issues, secrets, quality regressions, and AI-code mistakes before merge. [](#star-authenticity-audit) English | Deutsch | 简体中文 | Translations Skylos is an open-source static analysis CLI for Python, TypeScript, JavaScript, Java, Go, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment config. It runs locally by default and can also be used as…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 0 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
Open-source, local-first checks for dead code, security issues, secrets, quality regressions, and AI-code mistakes before merge. [](#star-authenticity-audit) English | Deutsch | 简体中文 | Translations Skylos is an open-source static analysis CLI for Python, TypeScript, JavaScript, Java, Go, Kotlin, PHP, Rust, Dart, C#, Shell, and deployment config. It runs locally by default and can also be used as a CI/CD PR gate. Use Skylos when you want one command to check a repo or pull request for: dead code…
Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.