Agent skill

Sonarqube

by 686f6c61 in 686f6c61/alfred-dev

Levantar SonarQube con Docker, analizar el código y proponer mejoras.

MITAuto-check: notesDevOps & Cloud

Install Sonarqube

skills CLI
$ npx skills add 686f6c61/alfred-dev --skill sonarqube -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 686f6c61/alfred-dev sonarqube --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/686f6c61/alfred-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sonarqube .claude/skills/sonarqube && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonarqube
GitHub stars
117
Token cost
~1.6k tokens
SKILL.md length
722 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Levantar SonarQube con Docker, analizar el código y proponer mejoras.

  • Tasks that involve Containers
  • SKILL.md covers Resumen, Proceso, Qué NO hacer and Referencia al stack
  • Calls docker, brew and curl; reaches get.docker.com
  • Tasks that involve Refactoring

What it does

Sonarqube is an agent skill from 686f6c61/alfred-dev. Levantar SonarQube con Docker, analizar el código y proponer mejoras. También: análisis estático, deuda técnica, code smells, cobertura, calidad automatizada.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Refactoring. It works with Docker and Linux. The repository describes itself as: Tu equipo de desarrolladores en un plugin. 10 agentes, 11 skills planas, 18 comandos /alfred-dev:. Memoria persistente, quality gates con evidencia y MCP local. The licence is MIT.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve Refactoring

Example prompts

  • “/sonarqube”

Requirements

  • Python 3
  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit be0b51e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • brew
    • curl
    • sh
    • winget
    • npx
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • get.docker.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sonarqube loads about 1.6k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 722 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePipes a well-known installer script into a shellSKILL.md:43
    curl -fsSL https://get.docker.com | sh
  • NoteRuns commands with sudoSKILL.md:44
    sudo systemctl start docker
  • NoteRuns commands with sudoSKILL.md:45
    sudo usermod -aG docker $USER
  • NoteRuns commands with sudoSKILL.md:62
    sudo systemctl start docker

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from 686f6c61/alfred-dev at commit be0b51e, republished under its MIT licence (© 686f6c61). 722 words, ~1,593 tokens.

Download SKILL.mdSave it as .claude/skills/sonarqube/SKILL.md (or your agent's skills folder).
name
sonarqube
description
Levantar SonarQube con Docker, analizar el código y proponer mejoras. También: análisis estático, deuda técnica, code smells, cobertura, calidad automatizada.
disable-model-invocation
true

Análisis de calidad con SonarQube

Resumen

Este skill levanta una instancia de SonarQube con Docker, ejecuta un análisis del código del proyecto y traduce los resultados en propuestas de mejora accionables. SonarQube detecta bugs, vulnerabilidades, code smells y problemas de cobertura que las herramientas de linting no cubren.

No sustituye al qa-engineer ni al security-officer: complementa su trabajo con una segunda opinión automatizada basada en reglas estáticas probadas en millones de proyectos.

Proceso

Paso 1: preflight de Docker y permisos

Comprobar si Docker está disponible y si el daemon responde:

bash
docker --version
docker info

Interpreta el resultado con estas reglas:

  • Si docker --version falla: Docker no está instalado. Explica al usuario que SonarQube lo necesita y que la instalación puede requerir permisos de administrador.
  • Si docker --version funciona pero docker info falla: Docker está instalado, pero el daemon no está disponible. Explica al usuario que hay que arrancar Docker Desktop o el servicio del sistema antes de continuar.

No instales Docker, no abras Docker Desktop y no arranques el daemon sin aprobación explícita del usuario. Si la orden viene desde /alfred audit, respeta la decisión tomada en su preflight. Si no existe una autorización previa, pídela ahora y espera respuesta.

Si el usuario autoriza la instalación, instala la última versión estable según la plataforma:

macOS:

bash
brew install --cask docker
open -a Docker

Linux (Ubuntu/Debian):

bash
curl -fsSL https://get.docker.com | sh
sudo systemctl start docker
sudo usermod -aG docker $USER

Windows (PowerShell como administrador):

powershell
winget install Docker.DockerDesktop

Si el usuario autoriza arrancar Docker cuando está instalado pero el daemon no responde, usa la estrategia mínima necesaria para la plataforma:

macOS:

bash
open -a Docker

Linux (systemd):

bash
sudo systemctl start docker

Windows (PowerShell):

powershell
Start-Process "C:\Program Files\Docker\Docker\Docker Desktop.exe"

Después de instalar o arrancar Docker, verifica otra vez con docker info.

  • Si docker info responde correctamente, continúa.
  • Si el usuario rechaza la instalación o el arranque, o si el daemon sigue sin responder, detén aquí la rama de SonarQube y devuelve un resultado explícito: "SonarQube omitido por decisión del usuario o por falta de permisos". No intentes forzarlo por otras vías.
Paso 2: levantar SonarQube

Antes de levantar el contenedor:

  • Comprueba si ya existe sonarqube-alfred. Si existe de una ejecución anterior, elimínalo primero para evitar conflictos:
bash
docker rm -f sonarqube-alfred 2>/dev/null || true
  • Comprueba si el puerto 9000 ya está en uso. Si lo está, detén la ejecución y pregunta al usuario si quiere liberar ese puerto o continuar sin SonarQube. No mates procesos por tu cuenta.
bash
docker run -d --name sonarqube-alfred -p 9000:9000 sonarqube:community

Esperar a que SonarQube esté listo (puede tardar 1-2 minutos):

Usa este bucle exacto o uno equivalente. No uses la variable status en scripts de shell: en zsh es de solo lectura y romperá la espera. Si necesitas guardar el estado en una variable, usa sonar_status.

bash
until curl -s http://localhost:9000/api/system/status | grep -q '"status":"UP"'; do sleep 5; done

Credenciales por defecto: admin/admin. Cambiar la contraseña en el primer acceso.

Show full SKILL.md (300 more words)Show less
Paso 3: configurar el proyecto
  • Crear un proyecto en SonarQube (vía API o interfaz web).
  • Generar un token de autenticación para el análisis.
  • Crear o verificar el fichero sonar-project.properties en la raíz del proyecto:
properties
sonar.projectKey=nombre-del-proyecto
sonar.sources=src
sonar.tests=tests
sonar.language=ts
sonar.sourceEncoding=UTF-8

Adaptar según el stack del proyecto (lenguaje, directorios de código y tests).

Paso 4: ejecutar el análisis

Para proyectos Node/TypeScript:

bash
npx sonarqube-scanner

Para proyectos Python:

bash
pip install pysonar-scanner && pysonar-scanner

Alternativa universal con Docker:

bash
docker run --rm -v "$(pwd):/usr/src" sonarsource/sonar-scanner-cli
Paso 5: interpretar resultados

Acceder a http://localhost:9000 y revisar el dashboard del proyecto. Clasificar los hallazgos por:

  • Bugs: errores que pueden causar comportamiento incorrecto. Prioridad alta.
  • Vulnerabilidades: problemas de seguridad detectados por reglas OWASP/CWE. Notificar al security-officer.
  • Code smells: problemas de mantenibilidad. Priorizar los de mayor impacto.
  • Cobertura: porcentaje de código cubierto por tests. Identificar zonas sin cobertura críticas.
Paso 6: generar informe de mejoras

Crear un informe con:

  • Resumen ejecutivo: métricas principales (bugs, vulnerabilidades, cobertura, deuda técnica).
  • Top 10 hallazgos por impacto con la corrección propuesta.
  • Zonas de código con mayor densidad de problemas.
  • Comparación con el análisis anterior si existe.
Paso 7: limpiar

Cuando el análisis esté completo y los resultados revisados:

bash
docker stop sonarqube-alfred && docker rm sonarqube-alfred

Si el análisis falla a mitad del proceso, intenta igualmente la limpieza final del contenedor temporal antes de salir.

Qué NO hacer

  • No dejar SonarQube corriendo indefinidamente. Es una herramienta de análisis puntual, no un servicio permanente.
  • No instalar Docker, arrancar el daemon ni abrir Docker Desktop sin permiso explícito del usuario.
  • No tratar todos los hallazgos como iguales. Priorizar por impacto real, no por cantidad.
  • No corregir hallazgos sin entender por qué SonarQube los marca. A veces los falsos positivos existen.
  • No sustituir los code reviews humanos por SonarQube. Son complementarios.

Referencia al stack

Consultar el stack detectado en la configuración de Alfred para seleccionar el scanner adecuado (Node.js, Python, etc.) y configurar automáticamente el fichero sonar-project.properties con el lenguaje y los directorios correctos.

© 686f6c61, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sonarqube of 686f6c61/alfred-dev.

Open the folder on GitHubat commit be0b51e

Compare with similar skills

Sonarqube next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonarqube compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonarqube this skill686f6c61/alfred-dev117—~1.6kAutomated safety check: NotesMIT
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider174—~2.6kAutomated safety check: PassCustom licence
Reproduce Issuenrwl/nx29k—~2.6kAutomated safety check: NotesMIT
CI Adhoc Testnubjs/nub4.4k—~1.7kAutomated safety check: PassMIT
Releasing MarchatCod-e-Codes/marchat137—~801Automated safety check: PassMIT

Similar skills

  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • The single skill for reproducing an nx issue. An agent skill from nrwl/nx.

    29k GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • CI Adhoc Test

    nubjs/nub

    Run ad-hoc / exploratory tests on a real OS or platform via CI when the behavior CANNOT be reproduced on the local host or in Docker — macOS Seatbelt / sandbox-exec / codesigning, Windows cmd.exe /…

    4.4k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Releasing Marchat

    Cod-e-Codes/marchat

    Prepares marchat releases: version bumps, CHANGELOG, packaging checksums, GitHub Actions release workflow, and Docker tags.

    137 GitHub stars~801 tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Swig CI Repro

    swig/swig

    Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…

    6.3k GitHub stars~1.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from 686f6c61/alfred-dev

All 11 skills in this repo
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Memory

    686f6c61/alfred-dev

    This skill should be used when the user asks to record a design decision, search past project decisions, inspect the Alfred memory timeline, or work with the alfred-memory MCP server.

    117 GitHub stars~601 tokensUpdated 1 mo ago
    Auto-check passed
  • PR Workflow

    686f6c61/alfred-dev

    Crear pull requests completas con descripcion, labels y reviewers

    117 GitHub stars~777 tokensUpdated 1 mo ago
    Auto-check passed
  • Style Direction

    686f6c61/alfred-dev

    Abrir y operar el companion visual de Selina para elegir una direccion de estilo en proyectos con interfaz.

    117 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Sync Project Docs

    686f6c61/alfred-dev

    Usar para sincronizar la documentación viva del proyecto después de una fase.

    117 GitHub stars~382 tokensUpdated 1 mo ago
    Auto-check passed
  • Write Adr

    686f6c61/alfred-dev

    Usar para escribir o cerrar un Architecture Decision Record.

    117 GitHub stars~421 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Sonarqube

What does Sonarqube do?

Levantar SonarQube con Docker, analizar el código y proponer mejoras. Sonarqube is an agent skill from 686f6c61/alfred-dev. Levantar SonarQube con Docker, analizar el código y proponer mejoras.

When should I use Sonarqube?

Sonarqube fits situations like: tasks that involve Containers; tasks that involve Refactoring.

How do I install Sonarqube in Claude Code?

Run `npx skills add 686f6c61/alfred-dev --skill sonarqube -a claude-code`. Or copy the skill folder (skills/sonarqube in 686f6c61/alfred-dev) into .claude/skills/sonarqube in your project. Claude Code loads it when a task matches its description.

How do I install Sonarqube in Codex?

Run `npx skills add 686f6c61/alfred-dev --skill sonarqube -a codex`. Or copy the skill folder (skills/sonarqube in 686f6c61/alfred-dev) into .agents/skills/sonarqube in your project. Codex loads it when a task matches its description.

Can I use Sonarqube in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 686f6c61/alfred-dev --skill sonarqube -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarqube, .gemini/skills/sonarqube, .github/skills/sonarqube and .opencode/skills/sonarqube in your project.

What does Sonarqube need to run?

Going by SKILL.md and its folder, Sonarqube needs the command-line tools its instructions call (docker, brew, curl, sh, winget and npx). Our summary lists: Python 3; Node.js; Docker.

Does Sonarqube access the network?

SKILL.md names 1 domain. In commands or code: get.docker.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sonarqube safe to install?

Our automated static check of SKILL.md found notes only (pipes a well-known installer script into a shell; runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sonarqube use?

Sonarqube is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sonarqube use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sonarqube?

Skills that share tags, products or a category with Sonarqube: .NET Crash Dump Collection (dotnet/skills, 5.6k stars), Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars), Reproduce Issue (nrwl/nx, 29k stars) and CI Adhoc Test (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonarqube?

686f6c61 (a GitHub user) maintains it in 686f6c61/alfred-dev, which has 117 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on August 15, 2026.

Source: 686f6c61/alfred-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.