Quality CI
managedcode/dotnet-skills
Set up or refine open-source .NET code-quality gates for CI: formatting, .editorconfig, SDK analyzers, third-party analyzers, coverage, mutation testing, architecture tests, and security scanning.
Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.
$ npx skills add aehrc/pathling --skill sonarcloud-api -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aehrc/pathling sonarcloud-api --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sonarcloud-api .claude/skills/sonarcloud-api && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sonarcloud-api" agent skill from https://github.com/aehrc/pathling/tree/main/.claude/skills/sonarcloud-api into .claude/skills/sonarcloud-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarcloud-api", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aehrc/pathling/tree/main/.claude/skills/sonarcloud-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aehrc/pathling --skill sonarcloud-api -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aehrc/pathling sonarcloud-api --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/sonarcloud-api .agents/skills/sonarcloud-api && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sonarcloud-api" agent skill from https://github.com/aehrc/pathling/tree/main/.claude/skills/sonarcloud-api into .agents/skills/sonarcloud-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarcloud-api", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aehrc/pathling --skill sonarcloud-api -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aehrc/pathling sonarcloud-api --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/sonarcloud-api .cursor/skills/sonarcloud-api && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sonarcloud-api" agent skill from https://github.com/aehrc/pathling/tree/main/.claude/skills/sonarcloud-api into .cursor/skills/sonarcloud-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarcloud-api", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aehrc/pathling.git --path .claude/skills/sonarcloud-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aehrc/pathling --skill sonarcloud-api -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aehrc/pathling sonarcloud-api --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/sonarcloud-api .gemini/skills/sonarcloud-api && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sonarcloud-api" agent skill from https://github.com/aehrc/pathling/tree/main/.claude/skills/sonarcloud-api into .gemini/skills/sonarcloud-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarcloud-api", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aehrc/pathling sonarcloud-apiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aehrc/pathling --skill sonarcloud-api -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/sonarcloud-api .github/skills/sonarcloud-api && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sonarcloud-api" agent skill from https://github.com/aehrc/pathling/tree/main/.claude/skills/sonarcloud-api into .github/skills/sonarcloud-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarcloud-api", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aehrc/pathling --skill sonarcloud-api -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aehrc/pathling sonarcloud-api --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aehrc/pathling.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/sonarcloud-api .opencode/skills/sonarcloud-api && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sonarcloud-api" agent skill from https://github.com/aehrc/pathling/tree/main/.claude/skills/sonarcloud-api into .opencode/skills/sonarcloud-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarcloud-api", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sonarcloud-apiExpert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.
Sonarcloud API is an agent skill from aehrc/pathling. Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics. Use this skill when making API calls to SonarCloud, automating code quality workflows, retrieving analysis results, managing projects programmatically, or integrating SonarCloud with CI/CD pipelines. Trigger keywords include "SonarCloud", "SonarCloud API", "code quality API", "SonarQube Cloud", "quality gate", "code analysis API", "SonarCloud measures", "SonarCloud issues".
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/metrics.md`, `references/v1-api.md` and `references/v2-api.md`).
It sits in Testing & QA, covering Quality gates, CI/CD and Code quality. The repository describes itself as: Tools that make it easier to use FHIR and clinical terminology within data analytics, built on Apache Spark. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 56a3b4a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
sonarcloud.ioapi.sonarcloud.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SONAR_TOKENSONAR_PROJECT_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sonarcloud API loads about 1.2k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 234 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aehrc/pathling at commit 56a3b4a, republished under its Apache-2.0 licence (© aehrc). 234 words, ~1,158 tokens.
.claude/skills/sonarcloud-api/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.SonarCloud provides two API versions for programmatic access:
https://api.sonarcloud.io/api/v2/https://sonarcloud.io/api/ with comprehensive endpoint coverage# Get project metrics
curl -X GET "https://sonarcloud.io/api/measures/component?component=my_project&metricKeys=bugs,vulnerabilities,code_smells" \
-H "Authorization: Bearer YOUR_TOKEN"Use bearer token authentication for all requests:
Authorization: Bearer <token>| Token Type | Plan | Scope | Use Case |
|---|---|---|---|
| Personal Access Token | Free | User-level | Individual API access |
| Organisation Token | Team | Organisation-scoped | CI/CD, automation |
Generate tokens at Account > Security > Generate Tokens in SonarCloud UI.
| API Version | Base URL |
|---|---|
| Web API v1 | https://sonarcloud.io/api/ |
| Web API v2 | https://api.sonarcloud.io/api/v2/ |
Content-Type: application/x-www-form-urlencoded (v1) or application/json (v2)
For POST requests, use form data parameters rather than URI query parameters.
Requests are rate-limited. When exceeded, the API returns HTTP 429. Wait several minutes before retrying.
Most list endpoints support pagination with p (page number) and ps (page size) parameters.
curl -X GET "https://sonarcloud.io/api/qualitygates/project_status?projectKey=my_project" \
-H "Authorization: Bearer YOUR_TOKEN"curl -X GET "https://sonarcloud.io/api/issues/search?componentKeys=my_project&types=BUG,VULNERABILITY" \
-H "Authorization: Bearer YOUR_TOKEN"curl -X GET "https://sonarcloud.io/api/measures/component?component=my_project&metricKeys=ncloc,coverage,duplicated_lines_density" \
-H "Authorization: Bearer YOUR_TOKEN"# v2 API
curl -X GET "https://api.sonarcloud.io/api/v2/projects?organization=my_org" \
-H "Authorization: Bearer YOUR_TOKEN"For detailed endpoint documentation, see the reference files:
| Status Code | Meaning |
|---|---|
| 400 | Bad request - check parameters |
| 401 | Unauthorised - invalid or missing token |
| 403 | Forbidden - insufficient permissions |
| 404 | Not found - resource does not exist |
| 429 | Rate limited - wait and retry |
| 500 | Server error |
- name: Check Quality Gate
run: |
STATUS=$(curl -s -H "Authorization: Bearer ${{ secrets.SONAR_TOKEN }}" \
"https://sonarcloud.io/api/qualitygates/project_status?projectKey=${{ vars.SONAR_PROJECT_KEY }}" \
| jq -r '.projectStatus.status')
if [ "$STATUS" != "OK" ]; then
echo "Quality Gate failed"
exit 1
ficheck_quality_gate:
script:
- |
STATUS=$(curl -s -H "Authorization: Bearer $SONAR_TOKEN" \
"https://sonarcloud.io/api/qualitygates/project_status?projectKey=$SONAR_PROJECT_KEY" \
| jq -r '.projectStatus.status')
if [ "$STATUS" != "OK" ]; then exit 1; fi© aehrc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in .claude/skills/sonarcloud-api of aehrc/pathling.
Open the folder on GitHubat commit 56a3b4a
Sonarcloud API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sonarcloud API this skillaehrc/pathling | 137 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Quality CImanagedcode/dotnet-skills | 486 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Quality Scandiegosouzapw/OmniRoute | 74k | — | ~748 | Automated safety check: Pass | MIT | |
| Dev ReviewFHIR/fhir-codegen | 154 | — | ~5k | Automated safety check: Pass | MIT | |
| Ways Of Workingdevantler-tech/ksail | 166 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Ship GateHouseofmvps/ultraship | 123 | — | ~1k | Automated safety check: Notes | MIT |
managedcode/dotnet-skills
Set up or refine open-source .NET code-quality gates for CI: formatting, .editorconfig, SDK analyzers, third-party analyzers, coverage, mutation testing, architecture tests, and security scanning.
diegosouzapw/OmniRoute
Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance.
FHIR/fhir-codegen
Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.
devantler-tech/ksail
Codifies devantler-tech engineering practices: agent-first development workflow, TDD, CI/CD pipelines, GitHub Flow, code quality gates, and Kubernetes workflows with ksail.
Houseofmvps/ultraship
Turn the /ship scorecard into a blocking, config-as-code quality gate.
LeoYeAI/openclaw-master-skills
AI Agent Skill unit testing framework. An agent skill from LeoYeAI/openclaw-master-skills.
aehrc/pathling
Expert guidance for implementing FHIR RESTful API servers and clients following the HL7 FHIR specification.
aehrc/pathling
Expert guidance for implementing FHIR Bulk Data Access (Flat FHIR) following the HL7 specification.
aehrc/pathling
Expert guidance for using the Databricks CLI to manage Databricks workspaces, clusters, jobs, pipelines, Unity Catalog, SQL warehouses, serving endpoints, secrets, bundles, and all other Databricks…
aehrc/pathling
FHIR RESTful search specification expert with access to the official HL7 search specification text and the formal SearchParameter registry.
aehrc/pathling
Design and generate comprehensive FHIRPath test suites using input domain partitioning and Pathling's DSL test framework.
aehrc/pathling
Expert guidance for implementing FHIR servers using HAPI FHIR Plain Server framework.
Categories
Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics. Sonarcloud API is an agent skill from aehrc/pathling. Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.
Sonarcloud API fits situations like: making API calls to SonarCloud; automating code quality workflows; retrieving analysis results; managing projects programmatically.
Run `npx skills add aehrc/pathling --skill sonarcloud-api -a claude-code`. Or copy the skill folder (.claude/skills/sonarcloud-api in aehrc/pathling) into .claude/skills/sonarcloud-api in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aehrc/pathling --skill sonarcloud-api -a codex`. Or copy the skill folder (.claude/skills/sonarcloud-api in aehrc/pathling) into .agents/skills/sonarcloud-api in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aehrc/pathling --skill sonarcloud-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarcloud-api, .gemini/skills/sonarcloud-api, .github/skills/sonarcloud-api and .opencode/skills/sonarcloud-api in your project.
Going by SKILL.md and its folder, Sonarcloud API needs the command-line tools its instructions call (curl) and credentials named SONAR_TOKEN and SONAR_PROJECT_KEY. Our summary lists: A credential in YOUR_TOKEN; A credential in SONAR_TOKEN.
SKILL.md names 2 domains. In commands or code: sonarcloud.io and api.sonarcloud.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sonarcloud API is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sonarcloud API: Quality CI (managedcode/dotnet-skills, 486 stars), Quality Scan (diegosouzapw/OmniRoute, 74k stars), Dev Review (FHIR/fhir-codegen, 154 stars) and Ways Of Working (devantler-tech/ksail, 166 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aehrc (a GitHub organization) maintains it in aehrc/pathling, which has 137 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 7, 2026.
Source: aehrc/pathling on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.