Agent skill

Sonarcloud API

by aehrc in aehrc/pathling

Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.

Apache-2.0Auto-check passedTesting & QA

Install Sonarcloud API

skills CLI
$ npx skills add aehrc/pathling --skill sonarcloud-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aehrc/pathling sonarcloud-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sonarcloud-api .claude/skills/sonarcloud-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonarcloud-api
GitHub stars
137
Token cost
~1.2k tokens
SKILL.md length
234 words
Files
4 (incl. references)
Skills in repo
25
Repo updated
First seen
Licence
Apache-2.0

At a glance

Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.

  • Making API calls to SonarCloud
  • SKILL.md covers Overview, Quick start, Authentication and Base URLs, plus 7 more sections
  • Calls curl; reaches sonarcloud.io and api.sonarcloud.io; needs SONAR_TOKEN and SONAR_PROJECT_KEY
  • Automating code quality workflows

What it does

Sonarcloud API is an agent skill from aehrc/pathling. Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics. Use this skill when making API calls to SonarCloud, automating code quality workflows, retrieving analysis results, managing projects programmatically, or integrating SonarCloud with CI/CD pipelines. Trigger keywords include "SonarCloud", "SonarCloud API", "code quality API", "SonarQube Cloud", "quality gate", "code analysis API", "SonarCloud measures", "SonarCloud issues".

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/metrics.md`, `references/v1-api.md` and `references/v2-api.md`).

It sits in Testing & QA, covering Quality gates, CI/CD and Code quality. The repository describes itself as: Tools that make it easier to use FHIR and clinical terminology within data analytics, built on Apache Spark. The licence is Apache-2.0.

When your agent uses it

  • Making API calls to SonarCloud
  • Automating code quality workflows
  • Retrieving analysis results
  • Managing projects programmatically

Example prompts

  • “SonarCloud”
  • “SonarCloud API”
  • “code quality API”
  • “/sonarcloud-api”

Requirements

  • A credential in YOUR_TOKEN
  • A credential in SONAR_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 56a3b4a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • sonarcloud.io
    • api.sonarcloud.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN
    • SONAR_PROJECT_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sonarcloud API loads about 1.2k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 234 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aehrc/pathling at commit 56a3b4a, republished under its Apache-2.0 licence (© aehrc). 234 words, ~1,158 tokens.

Download SKILL.mdSave it as .claude/skills/sonarcloud-api/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
sonarcloud-api
description
Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics. Use this skill when making API calls to SonarCloud, automating code quality workflows, retrieving analysis results, managing projects programmatically, or integrating SonarCloud with CI/CD pipelines. Trigger keywords include "SonarCloud", "SonarCloud API", "code quality API", "SonarQube Cloud", "quality gate", "code analysis API", "SonarCloud measures", "SonarCloud issues".

SonarCloud API

Overview

SonarCloud provides two API versions for programmatic access:

  • Web API v2 - Modern REST API with OpenAPI specifications at https://api.sonarcloud.io/api/v2/
  • Web API v1 - Legacy API at https://sonarcloud.io/api/ with comprehensive endpoint coverage

Quick start

bash
# Get project metrics
curl -X GET "https://sonarcloud.io/api/measures/component?component=my_project&metricKeys=bugs,vulnerabilities,code_smells" \
  -H "Authorization: Bearer YOUR_TOKEN"

Authentication

Use bearer token authentication for all requests:

Authorization: Bearer <token>
Token types
Token TypePlanScopeUse Case
Personal Access TokenFreeUser-levelIndividual API access
Organisation TokenTeamOrganisation-scopedCI/CD, automation

Generate tokens at Account > Security > Generate Tokens in SonarCloud UI.

Base URLs

API VersionBase URL
Web API v1https://sonarcloud.io/api/
Web API v2https://api.sonarcloud.io/api/v2/

Request format

Content-Type: application/x-www-form-urlencoded (v1) or application/json (v2)

For POST requests, use form data parameters rather than URI query parameters.

Rate limiting

Requests are rate-limited. When exceeded, the API returns HTTP 429. Wait several minutes before retrying.

Pagination

Most list endpoints support pagination with p (page number) and ps (page size) parameters.

Common tasks

Get project quality gate status
bash
curl -X GET "https://sonarcloud.io/api/qualitygates/project_status?projectKey=my_project" \
  -H "Authorization: Bearer YOUR_TOKEN"
Search issues
bash
curl -X GET "https://sonarcloud.io/api/issues/search?componentKeys=my_project&types=BUG,VULNERABILITY" \
  -H "Authorization: Bearer YOUR_TOKEN"
Get component measures
bash
curl -X GET "https://sonarcloud.io/api/measures/component?component=my_project&metricKeys=ncloc,coverage,duplicated_lines_density" \
  -H "Authorization: Bearer YOUR_TOKEN"
List projects
bash
# v2 API
curl -X GET "https://api.sonarcloud.io/api/v2/projects?organization=my_org" \
  -H "Authorization: Bearer YOUR_TOKEN"

API reference

For detailed endpoint documentation, see the reference files:

  • v2-api.md - Modern v2 API endpoints (Projects, Quality Gates, Analysis, Organisations)
  • v1-api.md - Legacy v1 API endpoints (Issues, Measures, Components, Rules)
  • metrics.md - Available metric keys and their meanings

Error handling

Status CodeMeaning
400Bad request - check parameters
401Unauthorised - invalid or missing token
403Forbidden - insufficient permissions
404Not found - resource does not exist
429Rate limited - wait and retry
500Server error

CI/CD integration examples

GitHub Actions
yaml
- name: Check Quality Gate
  run: |
      STATUS=$(curl -s -H "Authorization: Bearer ${{ secrets.SONAR_TOKEN }}" \
        "https://sonarcloud.io/api/qualitygates/project_status?projectKey=${{ vars.SONAR_PROJECT_KEY }}" \
        | jq -r '.projectStatus.status')
      if [ "$STATUS" != "OK" ]; then
        echo "Quality Gate failed"
        exit 1
      fi
GitLab CI
yaml
check_quality_gate:
    script:
        - |
            STATUS=$(curl -s -H "Authorization: Bearer $SONAR_TOKEN" \
              "https://sonarcloud.io/api/qualitygates/project_status?projectKey=$SONAR_PROJECT_KEY" \
              | jq -r '.projectStatus.status')
            if [ "$STATUS" != "OK" ]; then exit 1; fi

© aehrc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .claude/skills/sonarcloud-api of aehrc/pathling.

  • SKILL.md
  • references/metrics.md
  • references/v1-api.md
  • references/v2-api.md

Open the folder on GitHubat commit 56a3b4a

Compare with similar skills

Sonarcloud API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonarcloud API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonarcloud API this skillaehrc/pathling137—~1.2kAutomated safety check: PassApache-2.0
Quality CImanagedcode/dotnet-skills486—~2.1kAutomated safety check: PassMIT
Quality Scandiegosouzapw/OmniRoute74k—~748Automated safety check: PassMIT
Dev ReviewFHIR/fhir-codegen154—~5kAutomated safety check: PassMIT
Ways Of Workingdevantler-tech/ksail166—~2kAutomated safety check: PassApache-2.0
Ship GateHouseofmvps/ultraship123—~1kAutomated safety check: NotesMIT

Similar skills

  • Quality CI

    managedcode/dotnet-skills

    Set up or refine open-source .NET code-quality gates for CI: formatting, .editorconfig, SDK analyzers, third-party analyzers, coverage, mutation testing, architecture tests, and security scanning.

    486 GitHub stars~2.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Quality Scan

    diegosouzapw/OmniRoute

    Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance.

    74k GitHub stars~748 tokensUpdated today
    Testing & QAAuto-check passed
  • Dev Review

    FHIR/fhir-codegen

    Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.

    154 GitHub stars~5k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Ways Of Working

    devantler-tech/ksail

    Codifies devantler-tech engineering practices: agent-first development workflow, TDD, CI/CD pipelines, GitHub Flow, code quality gates, and Kubernetes workflows with ksail.

    166 GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Ship Gate

    Houseofmvps/ultraship

    Turn the /ship scorecard into a blocking, config-as-code quality gate.

    123 GitHub stars~1k tokensUpdated 3 mo ago
    Testing & QAAuto-check: notes
  • Eval Skills

    LeoYeAI/openclaw-master-skills

    AI Agent Skill unit testing framework. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.3k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed

More from aehrc/pathling

All 25 skills in this repo
  • Fhir API

    aehrc/pathling

    Expert guidance for implementing FHIR RESTful API servers and clients following the HL7 FHIR specification.

    137 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Fhir Bulk Data

    aehrc/pathling

    Expert guidance for implementing FHIR Bulk Data Access (Flat FHIR) following the HL7 specification.

    137 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Databricks CLI

    aehrc/pathling

    Expert guidance for using the Databricks CLI to manage Databricks workspaces, clusters, jobs, pipelines, Unity Catalog, SQL warehouses, serving endpoints, secrets, bundles, and all other Databricks…

    137 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Fhir Search Spec

    aehrc/pathling

    FHIR RESTful search specification expert with access to the official HL7 search specification text and the formal SearchParameter registry.

    137 GitHub stars~649 tokensUpdated today
    Auto-check passed
  • Design and generate comprehensive FHIRPath test suites using input domain partitioning and Pathling's DSL test framework.

    137 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Hapi Fhir Server

    aehrc/pathling

    Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework.

    137 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Questions about Sonarcloud API

What does Sonarcloud API do?

Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics. Sonarcloud API is an agent skill from aehrc/pathling. Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.

When should I use Sonarcloud API?

Sonarcloud API fits situations like: making API calls to SonarCloud; automating code quality workflows; retrieving analysis results; managing projects programmatically.

How do I install Sonarcloud API in Claude Code?

Run `npx skills add aehrc/pathling --skill sonarcloud-api -a claude-code`. Or copy the skill folder (.claude/skills/sonarcloud-api in aehrc/pathling) into .claude/skills/sonarcloud-api in your project. Claude Code loads it when a task matches its description.

How do I install Sonarcloud API in Codex?

Run `npx skills add aehrc/pathling --skill sonarcloud-api -a codex`. Or copy the skill folder (.claude/skills/sonarcloud-api in aehrc/pathling) into .agents/skills/sonarcloud-api in your project. Codex loads it when a task matches its description.

Can I use Sonarcloud API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aehrc/pathling --skill sonarcloud-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarcloud-api, .gemini/skills/sonarcloud-api, .github/skills/sonarcloud-api and .opencode/skills/sonarcloud-api in your project.

What does Sonarcloud API need to run?

Going by SKILL.md and its folder, Sonarcloud API needs the command-line tools its instructions call (curl) and credentials named SONAR_TOKEN and SONAR_PROJECT_KEY. Our summary lists: A credential in YOUR_TOKEN; A credential in SONAR_TOKEN.

Does Sonarcloud API access the network?

SKILL.md names 2 domains. In commands or code: sonarcloud.io and api.sonarcloud.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Sonarcloud API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sonarcloud API use?

Sonarcloud API is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sonarcloud API use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.1k tokens, read only when the agent opens those files.

What are the alternatives to Sonarcloud API?

Skills that share tags, products or a category with Sonarcloud API: Quality CI (managedcode/dotnet-skills, 486 stars), Quality Scan (diegosouzapw/OmniRoute, 74k stars), Dev Review (FHIR/fhir-codegen, 154 stars) and Ways Of Working (devantler-tech/ksail, 166 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonarcloud API?

aehrc (a GitHub organization) maintains it in aehrc/pathling, which has 137 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 7, 2026.

Source: aehrc/pathling on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.