Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed…

MITAuto-check passedTesting & QA

Install Sonarqube

skills CLI
$ npx skills add DougTrajano/pydantic-ai-skills --skill sonarqube -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DougTrajano/pydantic-ai-skills sonarqube --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DougTrajano/pydantic-ai-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sonarqube .claude/skills/sonarqube && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonarqube
GitHub stars
378
Token cost
~2.2k tokens
SKILL.md length
1,050 words
Files
5 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed…

  • Works in 5 steps: Use a project key explicitly supplied by… → Inspect sonar.projectKey in… → Inspect SonarQube for IDE connected-mode… → …
  • Configure integrations
  • SKILL.md covers Start with a preflight, Resolve the project before…, Choose the correct analysis and Prefer dedicated read commands, plus 3 more sections
  • Calls git

What it does

Sonarqube is an agent skill from DougTrajano/pydantic-ai-skills. Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed code, scan secrets and dependency risks, call authenticated APIs, trigger remediation, configure integrations, and troubleshoot the CLI. Use whenever the user mentions SonarQube, SonarQube Cloud/SonarCloud, Sonar project details, quality gates, Sonar issues, sonar commands, agentic analysis, dependency risks, secrets…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `evals/evals.json`, `references/authentication.md` and `references/commands.md`). Compatibility notes: Requires the SonarQube CLI executable sonar; commands were verified against v1.7.0. Some operations require Git, a SonarQube Cloud plan or Server edition, or…

It sits in Testing & QA, covering Quality gates, Static analysis and SAST and Authentication. It works with Pydantic AI and Python. The repository describes itself as: This package implements Agent Skills (https://agentskills.io) support with progressive disclosure for Pydantic AI. Supports filesystem and programmatic skills. The licence is MIT.

When your agent uses it

  • Configure integrations
  • Troubleshoot the CLI
  • The user mentions SonarQube
  • SonarQube Cloud/SonarCloud

Example prompts

  • “/sonarqube”

Requirements

  • Compatibility (from SKILL.md): Requires the SonarQube CLI executable `sonar`; commands were verified against v1.7.0. Some operations require Git, a SonarQube Cloud plan or Server edition, or product-specific entitlements.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Use a project key explicitly supplied by the user.
  2. Inspect sonar.projectKey in sonar-project.properties at the repository root.
  3. Inspect SonarQube for IDE connected-mode binding under .sonarlint/, such as .sonarlint/connectedMode.json.
  4. Let the CLI auto-detect when the command supports it.
  5. Search accessible projects with sonar list projects -q and disambiguate multiple matches before continuing.

What it can do on your machine

Read from SKILL.md and the folder at commit cfdfcf5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the SonarQube CLI executable `sonar`; commands were verified against v1.7.0. Some operations require Git, a SonarQube Cloud plan or Server edition, or product-specific entitlements.

    From compatibility in the SKILL.md frontmatter.

Context cost

Sonarqube loads about 2.2k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 169 tokens; SKILL.md has 1,050 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~169
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DougTrajano/pydantic-ai-skills at commit cfdfcf5, republished under its MIT licence (© DougTrajano). 1,050 words, ~2,228 tokens.

Download SKILL.mdSave it as .claude/skills/sonarqube/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
sonarqube
description
Operate SonarQube-enabled repositories through the SonarQube CLI (`sonar`): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed code, scan secrets and dependency risks, call authenticated APIs, trigger remediation, configure integrations, and troubleshoot the CLI. Use whenever the user mentions SonarQube, SonarQube Cloud/SonarCloud, Sonar project details, quality gates, Sonar issues, `sonar` commands, agentic analysis, dependency risks, secrets scanning, or Sonar integrations, even if they do not explicitly name this skill. Do not use for generic static analysis unrelated to SonarQube.
compatibility
Requires the SonarQube CLI executable `sonar`; commands were verified against v1.7.0. Some operations require Git, a SonarQube Cloud plan or Server edition, or product-specific entitlements.

SonarQube CLI

Use the installed sonar CLI as the source of truth for a SonarQube-enabled project. Prefer structured, read-only inspection before analysis or mutation, and make the final response state the project, branch or pull request, command scope, and result.

Start with a preflight

Run these checks from the repository or worktree the user placed in scope:

bash
command -v sonar
sonar --version
sonar auth status

If the task involves installation state, integrations, or a confusing auth error, also run sonar system status --json.

Treat sonar auth status as the authoritative credential check. Do not infer authentication merely from a saved config file. In a sandbox, container, SSH session, or background agent, OS Keychain access may fail even though authentication works in the user's interactive terminal. Explain that distinction and use the environment-variable route in authentication.md when the user has made credentials available; never retrieve, print, or persist a token yourself.

The CLI is evolving. If the installed version differs from the reference snapshot or a command rejects an option, run sonar --help and sonar <command> --help, then follow the installed help. Read commands.md when selecting flags or when the user asks what the CLI supports.

Resolve the project before querying it

Use the exact project key, not the display name. Resolve it in this order:

  1. Use a project key explicitly supplied by the user.
  2. Inspect sonar.projectKey in sonar-project.properties at the repository root.
  3. Inspect SonarQube for IDE connected-mode binding under .sonarlint/, such as .sonarlint/connectedMode.json.
  4. Let the CLI auto-detect when the command supports it.
  5. Search accessible projects with sonar list projects -q <name-or-key> and disambiguate multiple matches before continuing.

Do not silently choose among multiple project matches. Read workflows.md for project-detail, issue, quality-gate, and API recipes.

Choose the correct analysis

IntentCommandImportant behavior
Analyze one or more changed source filessonar analyze --file <path>One file defaults to STANDARD; multiple files default to DEEP. --file is repeatable.
Analyze uncommitted Git changessonar analyzeRequires a Git repository and may run server-side analysis.
Analyze staged filessonar analyze --stagedUses git diff --cached.
Compare with a base refsonar analyze --base <ref>Analyze the change set relative to the named ref.
Request explicit cross-file analysissonar analyze --depth DEEPMore context and potentially more time/data transfer.
Invoke the explicit Vortex routesonar analyze agentic ...Server-side analysis; limitations and entitlements apply.
Scan files for hardcoded secretssonar analyze secrets <paths...>Scans paths or --stdin; treat a findings exit code as a finding, not an infrastructure failure.
Analyze dependency manifestssonar analyze dependency-risksUploads manifests for security/license analysis; product entitlement may be required.
Run a traditional full-project CI scanProject's existing scanner/build commandsonar analyze is not a replacement for every SonarScanner, Maven, Gradle, or .NET full-project pipeline. Inspect repository config and use the existing workflow only when requested.

Before server-side analysis, inspect the selected files or Git change set so the scope is known. Avoid --force unless the user has explicitly accepted bypassing the large-change-set confirmation. Prefer --format json for deterministic parsing and retain the command exit status.

After fixing findings, rerun the same analysis scope. Do not expand from a file scan to the entire change set without saying so.

If the selected Git scope is empty, report that no files were analyzed. An empty change set is not evidence that the repository is clean.

Prefer dedicated read commands

Use the narrowest command that answers the question:

bash
sonar list projects -q <query>
sonar list issues --project <key> --format json
sonar quality-gate status --project <key> --format json --all

Add exactly one of --branch <name> or --pull-request <id> when needed. They are mutually exclusive for quality-gate status. Paginate project and issue results rather than assuming the first page is complete.

For an agent-facing issue summary, --format toon is compact. Use JSON when filtering, joining, or producing exact counts; use table or CSV only when that presentation is requested.

Use sonar api get ... when dedicated commands do not expose enough detail. Start with read-only GET requests and consult the connected instance's API description when endpoint support is uncertain:

bash
sonar api get "/api/webservices/list"

API v1/v2 availability differs by Cloud region and Server version. The CLI rewrites supported v2 paths between Cloud and Server, but the server remains the authority. URL-encode project keys and other user-controlled query values.

Show full SKILL.md (366 more words)Show less

Handle state-changing commands deliberately

These commands can change local files, credentials, CLI state, code, or remote SonarQube state:

  • sonar remediate
  • sonar api post|patch|put|delete ...
  • sonar integrate ...
  • sonar auth login|logout
  • sonar config telemetry ...
  • sonar update
  • sonar system reset

Resolve exact targets and explain the effect before running them. Browser login must be performed manually by the user; agents cannot authenticate themselves. Never pass tokens in command arguments, logs, committed files, or chat output.

For sonar remediate, preview eligible issue keys with sonar list issues, limit the selection to the requested issues, and note that non-interactive use requires --issues with at most 20 comma-separated keys.

For sonar integrate, inspect existing hooks and agent configuration first because the command writes project or global configuration. Use --non-interactive only after all choices are known. Do not combine project selection with global mode where the installed help marks them mutually exclusive.

Treat sonar system reset --force as destructive: it removes tokens, managed binaries, integrations, and cached files. Run it only when the user explicitly asks for a reset. Likewise, run sonar auth logout, telemetry changes, or an update only on explicit request.

Report results clearly

For inspection tasks, report:

  • CLI version and authenticated target without exposing credentials
  • resolved project key and how it was resolved
  • branch or pull request scope
  • the requested result, including pagination or filters
  • any product/edition limitation or incomplete API response
  • a compact Queries run list naming the dedicated commands and GET endpoints used, so the result is auditable without exposing credentials

For analysis tasks, report files/change-set scope, depth, issue counts grouped usefully, exit status, and the next concrete remediation step. Never reproduce detected secret values; report only type and safe location metadata.

Troubleshoot methodically

When a command fails:

  1. Run its --help and compare flags with the installed version.
  2. Recheck sonar auth status and sonar system status --json.
  3. Confirm Cloud region or Server URL, organization, exact project key, branch/PR, and permissions.
  4. Distinguish authentication, entitlement/edition, network/proxy/TLS, Git-scope, and no-findings outcomes.
  5. Use sonar api ... --verbose only when needed and redact sensitive request or response data before reporting it.

Read authentication.md for credential and network guidance, workflows.md for complete operational recipes, and commands.md for the v1.7.0 command inventory.

© DougTrajano, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .claude/skills/sonarqube of DougTrajano/pydantic-ai-skills.

  • SKILL.md
  • evals/evals.json
  • references/authentication.md
  • references/commands.md
  • references/workflows.md

Open the folder on GitHubat commit cfdfcf5

Compare with similar skills

Sonarqube next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonarqube compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonarqube this skillDougTrajano/pydantic-ai-skills378—~2.2kAutomated safety check: PassMIT
Find Untested Sourcesdotnet/skills5.6k1 repos~3.3kAutomated safety check: PassMIT
Code SolvingHoangTheQuyen/think-better122—~3.7kAutomated safety check: PassMIT
Checkav1155/houndarr292—~366Automated safety check: PassAGPL-3.0
Sift Projectagent-labs-dev/fastbrowse114—~1.9kAutomated safety check: PassMIT
Review Pre Commitopenwpm/OpenWPM1.4k—~788Automated safety check: PassCustom licence

Similar skills

  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Testing & QAAuto-check passed
  • Code Solving

    HoangTheQuyen/think-better

    Structured coding workflow for non-trivial code work: debug, build features, refactor, optimize, migrate and review code through 7 steps with evidence-based quality gates.

    122 GitHub stars~3.7k tokensUpdated today
    Testing & QAAuto-check passed
  • Check

    av1155/houndarr

    Run Houndarr's full quality gate (ruff lint, ruff format check, mypy, bandit, pytest) and report results in a single table.

    292 GitHub stars~366 tokensUpdated 4 days ago
    Testing & QAAuto-check passed
  • Sift Project

    agent-labs-dev/fastbrowse

    Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse.

    114 GitHub stars~1.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Review Pre Commit

    openwpm/OpenWPM

    Use as a pre-commit quality gate — review the working diff for stub patterns (TODO/FIXME/unimplemented!()/todo!()), debug leftovers (dbg!, stray console.log/println!, commented-out code), then run…

    1.4k GitHub stars~788 tokensUpdated 5 days ago
    Testing & QAAuto-check passed
  • Pump Testing

    nirholas/pump-fun-sdk

    Multi-language test infrastructure for the Pump SDK — Rust unit/integration/security/performance tests, TypeScript Jest tests, Python fuzz tests, shell test orchestration, Criterion benchmarks, and…

    133 GitHub stars~706 tokensUpdated today
    Testing & QAAuto-check passed

Categories

Questions about Sonarqube

What does Sonarqube do?

Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed…. Sonarqube is an agent skill from DougTrajano/pydantic-ai-skills. Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed code, scan secrets and dependency risks, call authenticated APIs, trigger remediation, configure integrations, and troubleshoot the CLI.

When should I use Sonarqube?

Sonarqube fits situations like: configure integrations; troubleshoot the CLI; the user mentions SonarQube; sonarQube Cloud/SonarCloud.

How do I install Sonarqube in Claude Code?

Run `npx skills add DougTrajano/pydantic-ai-skills --skill sonarqube -a claude-code`. Or copy the skill folder (.claude/skills/sonarqube in DougTrajano/pydantic-ai-skills) into .claude/skills/sonarqube in your project. Claude Code loads it when a task matches its description.

How do I install Sonarqube in Codex?

Run `npx skills add DougTrajano/pydantic-ai-skills --skill sonarqube -a codex`. Or copy the skill folder (.claude/skills/sonarqube in DougTrajano/pydantic-ai-skills) into .agents/skills/sonarqube in your project. Codex loads it when a task matches its description.

Can I use Sonarqube in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DougTrajano/pydantic-ai-skills --skill sonarqube -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarqube, .gemini/skills/sonarqube, .github/skills/sonarqube and .opencode/skills/sonarqube in your project.

What does Sonarqube need to run?

Going by SKILL.md and its folder, Sonarqube needs the command-line tools its instructions call (git). Compatibility (from SKILL.md): Requires the SonarQube CLI executable `sonar`; commands were verified against v1.7.0. Some operations require Git, a SonarQube Cloud plan or Server edition, or product-specific entitlements..

Does Sonarqube access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sonarqube safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sonarqube use?

Sonarqube is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sonarqube use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.7k tokens, read only when the agent opens those files.

What are the alternatives to Sonarqube?

Skills that share tags, products or a category with Sonarqube: Find Untested Sources (dotnet/skills, 5.6k stars), Code Solving (HoangTheQuyen/think-better, 122 stars), Check (av1155/houndarr, 292 stars) and Sift Project (agent-labs-dev/fastbrowse, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonarqube?

DougTrajano (a GitHub user) maintains it in DougTrajano/pydantic-ai-skills, which has 378 GitHub stars. The repository was last updated on October 4, 2026.

Source: DougTrajano/pydantic-ai-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.