Suede MCP Release QA
JasonColapietro/suede-creator-skills
Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.
Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit sonarqube-mcp --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-tools/skills/sonarqube-mcp .claude/skills/sonarqube-mcp && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sonarqube-mcp" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-tools/skills/sonarqube-mcp into .claude/skills/sonarqube-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarqube-mcp", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-tools/skills/sonarqube-mcpType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit sonarqube-mcp --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/developer-kit-tools/skills/sonarqube-mcp .agents/skills/sonarqube-mcp && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sonarqube-mcp" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-tools/skills/sonarqube-mcp into .agents/skills/sonarqube-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarqube-mcp", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit sonarqube-mcp --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/developer-kit-tools/skills/sonarqube-mcp .cursor/skills/sonarqube-mcp && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sonarqube-mcp" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-tools/skills/sonarqube-mcp into .cursor/skills/sonarqube-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarqube-mcp", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/giuseppe-trisciuoglio/developer-kit.git --path plugins/developer-kit-tools/skills/sonarqube-mcp--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit sonarqube-mcp --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/developer-kit-tools/skills/sonarqube-mcp .gemini/skills/sonarqube-mcp && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sonarqube-mcp" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-tools/skills/sonarqube-mcp into .gemini/skills/sonarqube-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarqube-mcp", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install giuseppe-trisciuoglio/developer-kit sonarqube-mcpInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/developer-kit-tools/skills/sonarqube-mcp .github/skills/sonarqube-mcp && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sonarqube-mcp" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-tools/skills/sonarqube-mcp into .github/skills/sonarqube-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarqube-mcp", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit sonarqube-mcp --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/developer-kit-tools/skills/sonarqube-mcp .opencode/skills/sonarqube-mcp && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sonarqube-mcp" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-tools/skills/sonarqube-mcp into .opencode/skills/sonarqube-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sonarqube-mcp", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sonarqube-mcpProvides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server.
Sonarqube MCP is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server. Enables quality gate monitoring, issue discovery and triaging, pre-push code analysis, and rule education directly in the agent workflow. Use when the user wants to check quality gates, search for Sonar issues, analyze code snippets before committing, or understand SonarQube rules. Triggers on "sonarqube", "sonarcloud", "quality gate", "sonar issues", "analyze with sonar", "check sonar", "sonar rule", "pre-push…
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/best-practices.md`, `references/llm-context.md` and `references/metrics.md`).
It sits in Testing & QA, covering Quality gates, MCP servers and Third-party API integration. It works with Model Context Protocol and Docker. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json and bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comhub.docker.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SONARQUBE_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sonarqube MCP loads about 3.3k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 1,220 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 1,220 words, ~3,318 tokens.
.claude/skills/sonarqube-mcp/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Leverage SonarQube and SonarCloud capabilities directly through the Model Context Protocol (MCP) server to enforce code quality, discover issues, and run pre-push analysis inside the agent workflow.
This skill provides instructions and patterns for using the SonarQube MCP Server tools. It enables automated workflows for:
Use this skill when:
Trigger phrases: "check quality gate", "sonarqube quality gate", "find sonar issues", "search sonar issues", "analyze code with sonar", "check sonar rule", "sonarcloud issues", "pre-push sonar check", "sonar pre-commit"
The plugin includes a .mcp.json that starts the SonarQube MCP Server automatically via Docker. Before using this skill, set the required environment variables:
SonarQube Server (remote or local):
export SONARQUBE_TOKEN="squ_your_token"
export SONARQUBE_URL="https://sonarqube.mycompany.com" # or http://host.docker.internal:9000 for local DockerSonarCloud:
export SONARQUBE_TOKEN="squ_your_token"
export SONARQUBE_ORG="your-org-key" # required for SonarCloud
# SONARQUBE_URL is not needed for SonarCloudRequirements:
SONARQUBE_TOKEN is always requiredSONARQUBE_URL is required for SonarQube Server (use host.docker.internal for local instances)SONARQUBE_ORG is required for SonarCloud (omit SONARQUBE_URL in that case)Set your SonarQube/SonarCloud credentials:
# SonarQube Server
export SONARQUBE_TOKEN="squ_your_token"
export SONARQUBE_URL="https://sonarqube.mycompany.com"
# SonarCloud
export SONARQUBE_TOKEN="squ_your_token"
export SONARQUBE_ORG="your-org-key"Verify MCP tool availability:
mcp__sonarqube-mcp__<tool-name>If the MCP server fails to start, check:
references/metrics.md — Common SonarQube metrics and their meaningreferences/severity-levels.md — Sonar severity levels and impact categoriesreferences/best-practices.md — Workflows for PR checks and pre-commit analysisreferences/llm-context.md — Tool selection guide and parameter mapping for LLM agentsDetermine which operation the user needs:
| User Intent | Tool to Use |
|---|---|
| Check if project passes quality gate | get_project_quality_gate_status |
| Find critical issues in a project | search_sonar_issues_in_projects |
| Analyze code before committing | analyze_code_snippet |
| Understand a flagged rule | show_rule |
| Get detailed project metrics | get_component_measures |
| Mark an issue as false positive | change_sonar_issue_status |
If the user's intent is ambiguous, ask for the project key and the goal before proceeding.
Use get_project_quality_gate_status to verify a project meets its quality standards.
Parameters:
projectKey (string) — Project key in SonarQube/SonarCloudpullRequest (string, optional) — Pull request ID for PR-specific gate checkanalysisId (string, optional) — Specific analysis IDNote: There is no
branchparameter on this tool. Without apullRequestoranalysisId, the tool returns the quality gate status for the default branch.
Pattern — Check default branch gate:
{
"name": "get_project_quality_gate_status",
"arguments": {
"projectKey": "my-application"
}
}Pattern — Check PR gate before merge:
{
"name": "get_project_quality_gate_status",
"arguments": {
"projectKey": "backend-service",
"pullRequest": "456"
}
}Interpreting the response:
status: "OK" — Gate passed, safe to merge/deploystatus: "ERROR" — Gate failed; check conditions array for failing metricsmetricKey, actualValue, errorThreshold, comparatorFor more on metric keys, see references/metrics.md.
Use search_sonar_issues_in_projects to find and prioritize issues.
Parameters:
projects (array, optional) — List of project keys; omit to search all accessible projectsseverities (array, optional) — Filter: BLOCKER, HIGH, MEDIUM, LOW, INFOpullRequestId (string, optional) — Limit search to a specific PRp (integer, optional) — Page number (default: 1)ps (integer, optional) — Page size (default: 100, max: 500)Pattern — Find blockers and critical issues:
{
"name": "search_sonar_issues_in_projects",
"arguments": {
"projects": ["my-backend", "my-frontend"],
"severities": ["BLOCKER", "HIGH"],
"p": 1,
"ps": 50
}
}Pattern — Search issues in a PR:
{
"name": "search_sonar_issues_in_projects",
"arguments": {
"projects": ["my-service"],
"pullRequestId": "123",
"severities": ["HIGH", "MEDIUM"],
"p": 1,
"ps": 100
}
}Managing issues with change_sonar_issue_status:
Use this to mark false positives or accepted technical debt:
{
"name": "change_sonar_issue_status",
"arguments": {
"key": "AY1234",
"status": "falsepositive",
"comment": "This pattern is safe in our context because..."
}
}Valid statuses: falsepositive (not a real issue), accept (acknowledged technical debt), reopen (reset to open)
Always present the list of issues to the user before changing their status. Never autonomously mark issues as false positives without explicit user confirmation.
Use analyze_code_snippet to run SonarQube analysis on code before committing.
Parameters:
projectKey (string) — Project key for contextfileContent (string, required) — Full content of the file to analyzelanguage (string, optional) — Language hint for better accuracycodeSnippet (string, optional) — Narrow results to a specific sub-range within fileContentSupported languages: javascript, typescript, python, java, go, php, cs, cpp, kotlin, ruby, scala, swift
Pattern — Analyze TypeScript file before commit:
{
"name": "analyze_code_snippet",
"arguments": {
"projectKey": "my-typescript-app",
"fileContent": "async function fetchUser(id: string) {\n const query = `SELECT * FROM users WHERE id = ${id}`;\n return db.execute(query);\n}",
"language": "typescript"
}
}Pattern — Analyze Python file:
{
"name": "analyze_code_snippet",
"arguments": {
"projectKey": "my-python-service",
"fileContent": "import pickle\n\ndef load_model(path):\n with open(path, 'rb') as f:\n return pickle.load(f)",
"language": "python"
}
}Response interpretation:
ruleKey, severity, clean code attribute, impact category, line number, quick fix availabilityCRITICAL and HIGH severity issues before committingshow_rule with the ruleKey value for any unfamiliar ruleUse show_rule to understand why a rule exists and how to fix flagged code.
Parameters:
key (string) — Rule key in format <language>:<rule-id> (e.g., typescript:S1082, java:S2068)Pattern — Get rule documentation:
{
"name": "show_rule",
"arguments": {
"key": "typescript:S1082"
}
}Response includes: rule name, type, severity, full description, tags (e.g., cwe, owasp-a2), language, remediation effort estimate, code examples (non-compliant vs compliant).
Use get_component_measures to retrieve detailed metrics for a project, directory, or file.
Parameters:
projectKey (string) — Project key in SonarQube/SonarCloudpullRequest (string, optional) — PR ID for PR-scoped metricsmetricKeys (array) — List of metric keys to retrieveCommon metric keys: coverage, bugs, vulnerabilities, code_smells, complexity, cognitive_complexity, ncloc, duplicated_lines_density, new_coverage, new_bugs
Pattern — Project health dashboard:
{
"name": "get_component_measures",
"arguments": {
"projectKey": "my-project-key",
"metricKeys": ["coverage", "bugs", "vulnerabilities", "code_smells", "ncloc"]
}
}For full metric reference, see references/metrics.md.
After each tool call:
User request: "Check if the quality gate passes for project backend-api on PR #234"
{
"name": "get_project_quality_gate_status",
"arguments": {
"projectKey": "backend-api",
"pullRequest": "234"
}
}If gate fails: Extract failing conditions, present them to the user, then use search_sonar_issues_in_projects filtered by the same PR to show the actual issues.
User request: "Analyze this Go function before I push it"
{
"name": "analyze_code_snippet",
"arguments": {
"projectKey": "my-go-service",
"fileContent": "func handler(w http.ResponseWriter, r *http.Request) {\n id := r.URL.Query().Get(\"id\")\n query := fmt.Sprintf(\"SELECT * FROM orders WHERE id = %s\", id)\n rows, _ := db.Query(query)\n // ...\n}",
"language": "go"
}
}Present findings → for each issue, optionally call show_rule with the ruleKey value to explain the fix.
User request: "Show me all blocker issues in payment-service"
{
"name": "search_sonar_issues_in_projects",
"arguments": {
"projects": ["payment-service"],
"severities": ["BLOCKER"],
"p": 1,
"ps": 50
}
}Group results by category (Security, Reliability, Maintainability) and present to user. Offer to call show_rule for unfamiliar rules.
get_project_quality_gate_status as part of any PR review workflowanalyze_code_snippet during development, not only in CIshow_rule for unfamiliar keys — Never dismiss a rule without understanding its intentp and ps parameters; handle multi-page responses for complete coveragechange_sonar_issue_statuslanguage in analyze_code_snippet for more accurate analysisanalyze_code_snippet analyzes snippets in isolation — full project context may affect results in CIreferences/llm-context.mdpaging.total and paging.pageSize in the response to determine whether to iterate further pages© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in plugins/developer-kit-tools/skills/sonarqube-mcp of giuseppe-trisciuoglio/developer-kit.
Open the folder on GitHubat commit fe73fb3
Sonarqube MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sonarqube MCP this skillgiuseppe-trisciuoglio/developer-kit | 357 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Suede MCP Release QAJasonColapietro/suede-creator-skills | 127 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Sonar CoverageSonarSource/sonarqube-agent-plugins | 111 | — | ~2.1k | Automated safety check: Pass | Custom licence | |
| Pcb Designoaslananka/kicad-mcp-pro | 120 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Schematic Reviewoaslananka/kicad-mcp-pro | 120 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Sentry Issue Fixergenlayerlabs/genlayer-studio | 180 | — | ~2k | Automated safety check: Pass | MIT |
JasonColapietro/suede-creator-skills
Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.
SonarSource/sonarqube-agent-plugins
Find files with low test coverage and inspect uncovered lines in a SonarQube project (project key optional when MCP integration already defines the default project)
oaslananka/kicad-mcp-pro
Safe KiCad PCB design assistance workflow using KiCad MCP board inspection, placement, routing, stackup, and quality-gate tools.
oaslananka/kicad-mcp-pro
KiCad MCP schematic inspection and review workflow using ERC, connectivity, symbol, net, power, readability, and quality-gate tools.
genlayerlabs/genlayer-studio
Fetch, analyze, fix Sentry issues, run tests, and create PRs
SonarSource/sonarqube-agent-plugins
Show SonarQube quality gate status for a project — pass/fail and each condition (metric key, threshold, actual value), plus worst-offender breakdowns.
giuseppe-trisciuoglio/developer-kit
Generates complete CRUD modules for NestJS applications with Drizzle ORM.
giuseppe-trisciuoglio/developer-kit
Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.
giuseppe-trisciuoglio/developer-kit
Provides and generates complete CRUD workflows for Spring Boot 3 services.
giuseppe-trisciuoglio/developer-kit
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…
giuseppe-trisciuoglio/developer-kit
Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.
giuseppe-trisciuoglio/developer-kit
Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.
Works with
Categories
Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server. Sonarqube MCP is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server.
Sonarqube MCP fits situations like: the user wants to check quality gates; search for Sonar issues; analyze code snippets before committing; understand SonarQube rules.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a claude-code`. Or copy the skill folder (plugins/developer-kit-tools/skills/sonarqube-mcp in giuseppe-trisciuoglio/developer-kit) into .claude/skills/sonarqube-mcp in your project. Claude Code loads it when a task matches its description.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a codex`. Or copy the skill folder (plugins/developer-kit-tools/skills/sonarqube-mcp in giuseppe-trisciuoglio/developer-kit) into .agents/skills/sonarqube-mcp in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarqube-mcp, .gemini/skills/sonarqube-mcp, .github/skills/sonarqube-mcp and .opencode/skills/sonarqube-mcp in your project.
Going by SKILL.md and its folder, Sonarqube MCP needs credentials named SONARQUBE_TOKEN. Our summary lists: Python 3; Docker; A credential in SONARQUBE_TOKEN. Its frontmatter pre-approves these tools: Read.
SKILL.md names 2 domains. As links in the text: github.com and hub.docker.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sonarqube MCP is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sonarqube MCP: Suede MCP Release QA (JasonColapietro/suede-creator-skills, 127 stars), Sonar Coverage (SonarSource/sonarqube-agent-plugins, 111 stars), Pcb Design (oaslananka/kicad-mcp-pro, 120 stars) and Schematic Review (oaslananka/kicad-mcp-pro, 120 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.
Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.