How is this better than brakeman? (http://brakemanscanner.org/) Seems like they only pretty much check your gem dependencies while brakeman also does static code analysis and points out potential sql injection spots etc...
https://github.com/presidentbeef/brakeman/issues/276
A complementary command-line tool would be fine too.