Agent skill

Sonar

by ffroliva in ffroliva/gflow-cli

Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero.

MITAuto-check: notesTesting & QA

Install Sonar

skills CLI
$ npx skills add ffroliva/gflow-cli --skill sonar -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ffroliva/gflow-cli sonar --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sonar .claude/skills/sonar && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonar
GitHub stars
264
Token cost
~1.1k tokens
SKILL.md length
482 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero.

  • Works in 2 steps: Gate 🟢 GREEN: Proactively announce:… → Gate 🔴 RED: Fix identified code…
  • Tasks that involve Quality gates
  • SKILL.md covers Steps, Output, Pipeline Continuation (Next… and See also
  • Calls gh and jq; needs SONAR_TOKEN

What it does

Sonar is an agent skill from ffroliva/gflow-cli. Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero. Reports GREEN, or the exact PR-scoped new issues/hotspots/coverage gaps to fix.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Quality gates, Test coverage and AI video generation. It works with GitHub. The repository describes itself as: Drive Google Flow from the command line: Veo video and Imagen images, scripted, batched and pipeline-ready. Ships an MCP server so coding agents can drive it too, giving you and… The licence is MIT.

When your agent uses it

  • Tasks that involve Quality gates
  • Tasks that involve Test coverage
  • Tasks that involve AI video generation

Example prompts

  • “/sonar”

Requirements

  • A credential in SONAR_TOKEN

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Gate 🟢 GREEN: Proactively announce: "SonarCloud quality gate passed (zero new issues). Next step: Phase 10 Release Pipeline…
  2. Gate 🔴 RED: Fix identified code smells/coverage gaps, push, and re-run /gflow:sonar .

What it can do on your machine

Read from SKILL.md and the folder at commit cb6d501. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sonar loads about 1.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 482 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:42
    `.env.local` as `SONAR_TOKEN` — read it inside a sandbox so it never lands in chat.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ffroliva/gflow-cli at commit cb6d501, republished under its MIT licence (© ffroliva). 482 words, ~1,119 tokens.

Download SKILL.mdSave it as .claude/skills/sonar/SKILL.md (or your agent's skills folder).
name
sonar
description
Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero. Reports GREEN, or the exact PR-scoped new issues/hotspots/coverage gaps to fix.
version
1.0

/gflow:sonar [PR#] — SonarCloud quality gate

The reusable Sonar primitive. /gflow:check is local and cannot see Sonar (it is server-side, post-push); /gflow:pr-council-review is an LLM diff review, not the gate verdict. This command answers one question: is the SonarCloud gate green (zero new issues) for this PR, and if not, exactly what must be fixed?

$ARGUMENTS is the PR number. If empty, resolve it from the current branch (gh pr view --json number -q .number).

Project: key ffroliva_gflow-cli, org ffroliva-github (see sonar-project.properties). The CI scan sets sonar.qualitygate.wait=true, so a green SonarCloud analysis check means the gate genuinely passed — but the gate API is stale until that check finishes, so always check the GitHub check FIRST.

Steps

1. Check the GitHub check first (never trust the gate API while it's pending).

bash
gh pr checks <N> --json name,state,bucket | \
  jq -r '.[] | select(.name=="SonarCloud analysis") | "\(.bucket) \(.state)"'
  • pass → gate is GREEN / zero new issues. Done. Report GREEN and stop.
  • pending → the SonarCloud job (~50s) runs after the ~3.5min test matrix; wait (gh pr checks <N> --watch) before reading the API, or the API returns the previous commit's verdict.
  • fail → continue to step 2 to enumerate the exact failing conditions.

2. Enumerate the failing conditions (PR-scoped — this is the #1 gotcha).

New-code issues live on the PR branch, NOT main. Scope every call with &pullRequest=<N> or the API reports 0 and you chase phantoms. Token is in .env.local as SONAR_TOKEN — read it inside a sandbox so it never lands in chat. curl may be blocked by the context-mode hook → use ctx_execute (javascript fetch with Authorization: Basic base64(token+":")).

bash
# Which gate conditions are ERROR:
GET /api/qualitygates/project_status?projectKey=ffroliva_gflow-cli&pullRequest=<N>
# New issues (bugs/smells) with file:line + rule + creationDate:
GET /api/issues/search?componentKeys=ffroliva_gflow-cli&pullRequest=<N>&resolved=false
# Unreviewed security hotspots:
GET /api/hotspots/search?projectKey=ffroliva_gflow-cli&pullRequest=<N>&status=TO_REVIEW

3. Fix by condition — no gaming.

  • new_coverage < 80% → add real unit tests for the uncovered new lines (usually a new orchestration/_run_*/helper). There is NO mark-safe shortcut and NEVER widen sonar.coverage.exclusions to dodge it.
  • new_code_smells / new_maintainability_rating (e.g. S1192 duplicated literal, S3776 cognitive complexity) → fix at source. For a duplicated literal your diff merely touched, collapse it to one module-scope alias so it falls under the threshold (pyright/tests prove it's safe). For S7497, re-raise swallowed asyncio.CancelledError.
  • new_security_hotspots_reviewed < 100% → only for a genuine false positive: POST /api/hotspots/change_status form body hotspot=<key>&status=REVIEWED&resolution=SAFE&comment=<justification> (204 = ok), then re-run the SonarCloud job so it reposts the GitHub status (gh run rerun <run-id> --job <sonar-job-id> — the coverage artifact is reused). Never mark a real hotspot SAFE.
Show full SKILL.md (117 more words)Show less

4. Push fixes, then re-verify from step 1 (the check must read pass).

Output

  • Verdict: GREEN (gate passed, zero new issues) or RED with the exact failing conditions and a fix list (file:line · rule · what to do).
  • After any fix: re-confirm via step 1 — green check = gate passed.

Pipeline Continuation (Next Step Handoff)

Upon completing SonarCloud Quality Gate:

  1. Gate 🟢 GREEN: Proactively announce: "SonarCloud quality gate passed (zero new issues). Next step: Phase 10 Release Pipeline (/gflow:release) or merge PR."
  2. Gate 🔴 RED: Fix identified code smells/coverage gaps, push, and re-run /gflow:sonar <PR#>.

See also

  • docs/GITHUB.md § SonarCloud Quality Gate — full policy + coverage-exclusion rationale.
  • /gflow:check — the local pre-commit gates (coverage floor pre-empts new_coverage).
  • Memory: [[sonarcloud-pr-issues-scope-s7497]], [[sonarcloud-new-code-gotchas]], [[sonarcloud-hotspot-review-workflow]], [[sonarcloud-setup]].

© ffroliva, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sonar of ffroliva/gflow-cli.

Open the folder on GitHubat commit cb6d501

Compare with similar skills

Sonar next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonar compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonar this skillffroliva/gflow-cli264—~1.1kAutomated safety check: NotesMIT
Dev ReviewFHIR/fhir-codegen154—~5kAutomated safety check: PassMIT
Test Writing WorkflowiOfficeAI/AionUi33k1 repos~1.2kAutomated safety check: PassApache-2.0
Cherry Studio Regression TestsCherryHQ/cherry-studio52k—~1.2kAutomated safety check: PassAGPL-3.0
Reuse Before BuildAi-Eastern/reuse-before-build101—~5kAutomated safety check: PassMIT
Reviewwebern/cargo-readme385—~2kAutomated safety check: NotesApache-2.0

Similar skills

  • Dev Review

    FHIR/fhir-codegen

    Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.

    154 GitHub stars~5k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Test Writing Workflow

    iOfficeAI/AionUi

    Sets the test-writing workflow for the repository: risk-first scenario lists, behavior-focused Vitest tests, a full run before each commit and a coverage target.

    33k GitHub starsUsed in 1 repo~1.2k tokens
    Testing & QAAuto-check passed
  • Cherry Studio Regression Tests

    CherryHQ/cherry-studio

    Runs Cherry Studio's critical-path regression suite as deterministic Playwright E2E tests through a GitHub workflow on macOS and Windows runners.

    52k GitHub stars~1.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Reuse Before Build

    Ai-Eastern/reuse-before-build

    Discover reusable implementations and tests before architecture design, substantial changes, or test work.

    101 GitHub stars~5k tokensUpdated 12 days ago
    Testing & QAAuto-check passed
  • Review

    webern/cargo-readme

    Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.

    385 GitHub stars~2k tokensUpdated 12 days ago
    Testing & QAAuto-check: notes
  • A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

    446 GitHub stars~874 tokensUpdated yesterday
    Testing & QAAuto-check passed

More from ffroliva/gflow-cli

All 17 skills in this repo
  • Gflow CLI

    ffroliva/gflow-cli

    A skill your agent uses when the user wants to drive Google Flow (Veo image-to-video, Veo text-to-video, Imagen / Nano Banana image generation) from the terminal or a script — including…

    264 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check: notes
  • Issue Assessment

    ffroliva/gflow-cli

    A skill your agent uses when triaging a GitHub issue for gflow-cli — a reporter's bug claim, a freshly-filed issue, or deciding whether and how to act on one.

    264 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Issue Resolve

    ffroliva/gflow-cli

    A skill your agent uses when an assessed gflow-cli issue (verdict CONFIRMED-BUG or LIKELY-BUG) has localized, verifiable scope and should be driven to a fix.

    264 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Live Verify

    ffroliva/gflow-cli

    Two-part gate for gflow-cli feature/fix work. An agent skill from ffroliva/gflow-cli.

    264 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Video Production

    ffroliva/gflow-cli

    A skill your agent uses when the user wants a finished video out of gflow rather than a single clip — a scripted scene, a talking-head or dialogue piece, an explainer, a product montage, a story…

    264 GitHub stars~7k tokensUpdated yesterday
    Auto-check passed
  • Check

    ffroliva/gflow-cli

    Auto-fix lint and formatting, then report types and tests. An agent skill from ffroliva/gflow-cli.

    264 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Sonar

What does Sonar do?

Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero. Sonar is an agent skill from ffroliva/gflow-cli. Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero.

When should I use Sonar?

Sonar fits situations like: tasks that involve Quality gates; tasks that involve Test coverage; tasks that involve AI video generation.

How do I install Sonar in Claude Code?

Run `npx skills add ffroliva/gflow-cli --skill sonar -a claude-code`. Or copy the skill folder (skills/sonar in ffroliva/gflow-cli) into .claude/skills/sonar in your project. Claude Code loads it when a task matches its description.

How do I install Sonar in Codex?

Run `npx skills add ffroliva/gflow-cli --skill sonar -a codex`. Or copy the skill folder (skills/sonar in ffroliva/gflow-cli) into .agents/skills/sonar in your project. Codex loads it when a task matches its description.

Can I use Sonar in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ffroliva/gflow-cli --skill sonar -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonar, .gemini/skills/sonar, .github/skills/sonar and .opencode/skills/sonar in your project.

What does Sonar need to run?

Going by SKILL.md and its folder, Sonar needs the command-line tools its instructions call (gh and jq) and credentials named SONAR_TOKEN. Our summary lists: A credential in SONAR_TOKEN.

Does Sonar access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sonar safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sonar use?

Sonar is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sonar use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sonar?

Skills that share tags, products or a category with Sonar: Dev Review (FHIR/fhir-codegen, 154 stars), Test Writing Workflow (iOfficeAI/AionUi, 33k stars), Cherry Studio Regression Tests (CherryHQ/cherry-studio, 52k stars) and Reuse Before Build (Ai-Eastern/reuse-before-build, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonar?

ffroliva (a GitHub user) maintains it in ffroliva/gflow-cli, which has 264 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: ffroliva/gflow-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.