Dev Review
FHIR/fhir-codegen
Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.
Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero.
$ npx skills add ffroliva/gflow-cli --skill sonar -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ffroliva/gflow-cli sonar --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sonar .claude/skills/sonar && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sonar" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/sonar into .claude/skills/sonar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonar", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ffroliva/gflow-cli/tree/develop/skills/sonarType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ffroliva/gflow-cli --skill sonar -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ffroliva/gflow-cli sonar --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/sonar .agents/skills/sonar && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sonar" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/sonar into .agents/skills/sonar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonar", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ffroliva/gflow-cli --skill sonar -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ffroliva/gflow-cli sonar --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/sonar .cursor/skills/sonar && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sonar" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/sonar into .cursor/skills/sonar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonar", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ffroliva/gflow-cli.git --path skills/sonar--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ffroliva/gflow-cli --skill sonar -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ffroliva/gflow-cli sonar --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/sonar .gemini/skills/sonar && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sonar" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/sonar into .gemini/skills/sonar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonar", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ffroliva/gflow-cli sonarInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ffroliva/gflow-cli --skill sonar -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/sonar .github/skills/sonar && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sonar" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/sonar into .github/skills/sonar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonar", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ffroliva/gflow-cli --skill sonar -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ffroliva/gflow-cli sonar --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/sonar .opencode/skills/sonar && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sonar" agent skill from https://github.com/ffroliva/gflow-cli/tree/develop/skills/sonar into .opencode/skills/sonar/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonar", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sonarCheck the SonarCloud quality gate for a PR (or the current branch) and drive it to zero.
Sonar is an agent skill from ffroliva/gflow-cli. Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero. Reports GREEN, or the exact PR-scoped new issues/hotspots/coverage gaps to fix.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Testing & QA, covering Quality gates, Test coverage and AI video generation. It works with GitHub. The repository describes itself as: Drive Google Flow from the command line: Veo video and Imagen images, scripted, batched and pipeline-ready. Ships an MCP server so coding agents can drive it too, giving you and… The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cb6d501. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghjqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SONAR_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sonar loads about 1.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 482 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
`.env.local` as `SONAR_TOKEN` — read it inside a sandbox so it never lands in chat.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ffroliva/gflow-cli at commit cb6d501, republished under its MIT licence (© ffroliva). 482 words, ~1,119 tokens.
.claude/skills/sonar/SKILL.md (or your agent's skills folder)./gflow:sonar [PR#] — SonarCloud quality gateThe reusable Sonar primitive. /gflow:check is local and cannot see Sonar (it
is server-side, post-push); /gflow:pr-council-review is an LLM diff review, not the
gate verdict. This command answers one question: is the SonarCloud gate green
(zero new issues) for this PR, and if not, exactly what must be fixed?
$ARGUMENTS is the PR number. If empty, resolve it from the current branch
(gh pr view --json number -q .number).
Project: key ffroliva_gflow-cli, org ffroliva-github (see sonar-project.properties).
The CI scan sets sonar.qualitygate.wait=true, so a green SonarCloud analysis
check means the gate genuinely passed — but the gate API is stale until that
check finishes, so always check the GitHub check FIRST.
1. Check the GitHub check first (never trust the gate API while it's pending).
gh pr checks <N> --json name,state,bucket | \
jq -r '.[] | select(.name=="SonarCloud analysis") | "\(.bucket) \(.state)"'pass → gate is GREEN / zero new issues. Done. Report GREEN and stop.pending → the SonarCloud job (~50s) runs after the ~3.5min test matrix; wait
(gh pr checks <N> --watch) before reading the API, or the API returns the
previous commit's verdict.fail → continue to step 2 to enumerate the exact failing conditions.2. Enumerate the failing conditions (PR-scoped — this is the #1 gotcha).
New-code issues live on the PR branch, NOT main. Scope every call with
&pullRequest=<N> or the API reports 0 and you chase phantoms. Token is in
.env.local as SONAR_TOKEN — read it inside a sandbox so it never lands in chat.
curl may be blocked by the context-mode hook → use ctx_execute (javascript
fetch with Authorization: Basic base64(token+":")).
# Which gate conditions are ERROR:
GET /api/qualitygates/project_status?projectKey=ffroliva_gflow-cli&pullRequest=<N>
# New issues (bugs/smells) with file:line + rule + creationDate:
GET /api/issues/search?componentKeys=ffroliva_gflow-cli&pullRequest=<N>&resolved=false
# Unreviewed security hotspots:
GET /api/hotspots/search?projectKey=ffroliva_gflow-cli&pullRequest=<N>&status=TO_REVIEW3. Fix by condition — no gaming.
new_coverage < 80% → add real unit tests for the uncovered new lines
(usually a new orchestration/_run_*/helper). There is NO mark-safe shortcut and
NEVER widen sonar.coverage.exclusions to dodge it.new_code_smells / new_maintainability_rating (e.g. S1192 duplicated literal,
S3776 cognitive complexity) → fix at source. For a duplicated literal your diff
merely touched, collapse it to one module-scope alias so it falls under the
threshold (pyright/tests prove it's safe). For S7497, re-raise swallowed
asyncio.CancelledError.new_security_hotspots_reviewed < 100% → only for a genuine false positive:
POST /api/hotspots/change_status form body
hotspot=<key>&status=REVIEWED&resolution=SAFE&comment=<justification> (204 = ok),
then re-run the SonarCloud job so it reposts the GitHub status
(gh run rerun <run-id> --job <sonar-job-id> — the coverage artifact is reused).
Never mark a real hotspot SAFE.4. Push fixes, then re-verify from step 1 (the check must read pass).
file:line · rule · what to do).Upon completing SonarCloud Quality Gate:
/gflow:release) or merge PR."/gflow:sonar <PR#>.docs/GITHUB.md § SonarCloud Quality Gate — full policy + coverage-exclusion rationale./gflow:check — the local pre-commit gates (coverage floor pre-empts new_coverage).© ffroliva, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/sonar of ffroliva/gflow-cli.
Open the folder on GitHubat commit cb6d501
Sonar next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sonar this skillffroliva/gflow-cli | 264 | — | ~1.1k | Automated safety check: Notes | MIT | |
| Dev ReviewFHIR/fhir-codegen | 154 | — | ~5k | Automated safety check: Pass | MIT | |
| Test Writing WorkflowiOfficeAI/AionUi | 33k | 1 repos | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Cherry Studio Regression TestsCherryHQ/cherry-studio | 52k | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | |
| Reuse Before BuildAi-Eastern/reuse-before-build | 101 | — | ~5k | Automated safety check: Pass | MIT | |
| Reviewwebern/cargo-readme | 385 | — | ~2k | Automated safety check: Notes | Apache-2.0 |
FHIR/fhir-codegen
Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.
iOfficeAI/AionUi
Sets the test-writing workflow for the repository: risk-first scenario lists, behavior-focused Vitest tests, a full run before each commit and a coverage target.
CherryHQ/cherry-studio
Runs Cherry Studio's critical-path regression suite as deterministic Playwright E2E tests through a GitHub workflow on macOS and Windows runners.
Ai-Eastern/reuse-before-build
Discover reusable implementations and tests before architecture design, substantial changes, or test work.
webern/cargo-readme
Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.
jabrena/plinth
A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…
ffroliva/gflow-cli
A skill your agent uses when the user wants to drive Google Flow (Veo image-to-video, Veo text-to-video, Imagen / Nano Banana image generation) from the terminal or a script — including…
ffroliva/gflow-cli
A skill your agent uses when triaging a GitHub issue for gflow-cli — a reporter's bug claim, a freshly-filed issue, or deciding whether and how to act on one.
ffroliva/gflow-cli
A skill your agent uses when an assessed gflow-cli issue (verdict CONFIRMED-BUG or LIKELY-BUG) has localized, verifiable scope and should be driven to a fix.
ffroliva/gflow-cli
Two-part gate for gflow-cli feature/fix work. An agent skill from ffroliva/gflow-cli.
ffroliva/gflow-cli
A skill your agent uses when the user wants a finished video out of gflow rather than a single clip — a scripted scene, a talking-head or dialogue piece, an explainer, a product montage, a story…
ffroliva/gflow-cli
Auto-fix lint and formatting, then report types and tests. An agent skill from ffroliva/gflow-cli.
Works with
Categories
Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero. Sonar is an agent skill from ffroliva/gflow-cli. Check the SonarCloud quality gate for a PR (or the current branch) and drive it to zero.
Sonar fits situations like: tasks that involve Quality gates; tasks that involve Test coverage; tasks that involve AI video generation.
Run `npx skills add ffroliva/gflow-cli --skill sonar -a claude-code`. Or copy the skill folder (skills/sonar in ffroliva/gflow-cli) into .claude/skills/sonar in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ffroliva/gflow-cli --skill sonar -a codex`. Or copy the skill folder (skills/sonar in ffroliva/gflow-cli) into .agents/skills/sonar in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ffroliva/gflow-cli --skill sonar -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonar, .gemini/skills/sonar, .github/skills/sonar and .opencode/skills/sonar in your project.
Going by SKILL.md and its folder, Sonar needs the command-line tools its instructions call (gh and jq) and credentials named SONAR_TOKEN. Our summary lists: A credential in SONAR_TOKEN.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Sonar is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sonar: Dev Review (FHIR/fhir-codegen, 154 stars), Test Writing Workflow (iOfficeAI/AionUi, 33k stars), Cherry Studio Regression Tests (CherryHQ/cherry-studio, 52k stars) and Reuse Before Build (Ai-Eastern/reuse-before-build, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ffroliva (a GitHub user) maintains it in ffroliva/gflow-cli, which has 264 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.
Source: ffroliva/gflow-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.