Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server.

MITAuto-check passedTesting & QA

Install Sonarqube MCP

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit sonarqube-mcp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-tools/skills/sonarqube-mcp .claude/skills/sonarqube-mcp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonarqube-mcp
GitHub stars
357
Token cost
~3.3k tokens
SKILL.md length
1,220 words
Files
5 (incl. references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server.

  • Works in 7 steps: Identify the Required Operation → Quality Gate Monitoring → Issue Discovery and Triaging → …
  • The user wants to check quality gates
  • SKILL.md covers Overview, When to Use, Prerequisites and Setup and Quick Start, plus 5 more sections
  • Needs SONARQUBE_TOKEN

What it does

Sonarqube MCP is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server. Enables quality gate monitoring, issue discovery and triaging, pre-push code analysis, and rule education directly in the agent workflow. Use when the user wants to check quality gates, search for Sonar issues, analyze code snippets before committing, or understand SonarQube rules. Triggers on "sonarqube", "sonarcloud", "quality gate", "sonar issues", "analyze with sonar", "check sonar", "sonar rule", "pre-push…

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/best-practices.md`, `references/llm-context.md` and `references/metrics.md`).

It sits in Testing & QA, covering Quality gates, MCP servers and Third-party API integration. It works with Model Context Protocol and Docker. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • The user wants to check quality gates
  • Search for Sonar issues
  • Analyze code snippets before committing
  • Understand SonarQube rules

Example prompts

  • “sonarqube”
  • “sonarcloud”
  • “quality gate”
  • “/sonarqube-mcp”

Requirements

  • Python 3
  • Docker
  • A credential in SONARQUBE_TOKEN
  • Pre-approved tools (allowed-tools): Read

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Identify the Required Operation
  2. Quality Gate Monitoring
  3. Issue Discovery and Triaging
  4. Pre-Push Analysis (Shift Left)
  5. Rule Education
  6. Get Component Measures
  7. Present Results to User

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • hub.docker.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONARQUBE_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sonarqube MCP loads about 3.3k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 1,220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 1,220 words, ~3,318 tokens.

Download SKILL.mdSave it as .claude/skills/sonarqube-mcp/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
sonarqube-mcp
description
Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server. Enables quality gate monitoring, issue discovery and triaging, pre-push code analysis, and rule education directly in the agent workflow. Use when the user wants to check quality gates, search for Sonar issues, analyze code snippets before committing, or understand SonarQube rules. Triggers on "sonarqube", "sonarcloud", "quality gate", "sonar issues", "analyze with sonar", "check sonar", "sonar rule", "pre-push analysis".
allowed-tools
Read

SonarQube MCP Integration

Leverage SonarQube and SonarCloud capabilities directly through the Model Context Protocol (MCP) server to enforce code quality, discover issues, and run pre-push analysis inside the agent workflow.

Overview

This skill provides instructions and patterns for using the SonarQube MCP Server tools. It enables automated workflows for:

  • Checking quality gate status before merges or deployments
  • Discovering and triaging issues by severity and project
  • Analyzing code snippets locally before committing (shift-left)
  • Understanding SonarQube rules with full documentation

When to Use

Use this skill when:

  • The user wants to check if a project passes its quality gate before merging a PR
  • The user wants to find critical or blocker issues in one or more SonarQube projects
  • The user wants to analyze a code snippet for issues before pushing to CI
  • The user wants to understand why a specific Sonar rule flagged their code
  • The user asks for pre-commit or pre-push quality feedback

Trigger phrases: "check quality gate", "sonarqube quality gate", "find sonar issues", "search sonar issues", "analyze code with sonar", "check sonar rule", "sonarcloud issues", "pre-push sonar check", "sonar pre-commit"

Prerequisites and Setup

The plugin includes a .mcp.json that starts the SonarQube MCP Server automatically via Docker. Before using this skill, set the required environment variables:

SonarQube Server (remote or local):

bash
export SONARQUBE_TOKEN="squ_your_token"
export SONARQUBE_URL="https://sonarqube.mycompany.com"  # or http://host.docker.internal:9000 for local Docker

SonarCloud:

bash
export SONARQUBE_TOKEN="squ_your_token"
export SONARQUBE_ORG="your-org-key"   # required for SonarCloud
# SONARQUBE_URL is not needed for SonarCloud

Requirements:

  • Docker must be installed and running
  • SONARQUBE_TOKEN is always required
  • SONARQUBE_URL is required for SonarQube Server (use host.docker.internal for local instances)
  • SONARQUBE_ORG is required for SonarCloud (omit SONARQUBE_URL in that case)

Quick Start

  1. Set your SonarQube/SonarCloud credentials:

    bash
    # SonarQube Server
    export SONARQUBE_TOKEN="squ_your_token"
    export SONARQUBE_URL="https://sonarqube.mycompany.com"
    
    # SonarCloud
    export SONARQUBE_TOKEN="squ_your_token"
    export SONARQUBE_ORG="your-org-key"
  2. Verify MCP tool availability:

    • Tool names follow the pattern: mcp__sonarqube-mcp__<tool-name>
  3. If the MCP server fails to start, check:

Reference Documents

  • references/metrics.md — Common SonarQube metrics and their meaning
  • references/severity-levels.md — Sonar severity levels and impact categories
  • references/best-practices.md — Workflows for PR checks and pre-commit analysis
  • references/llm-context.md — Tool selection guide and parameter mapping for LLM agents

Instructions

Step 1: Identify the Required Operation

Determine which operation the user needs:

User IntentTool to Use
Check if project passes quality gateget_project_quality_gate_status
Find critical issues in a projectsearch_sonar_issues_in_projects
Analyze code before committinganalyze_code_snippet
Understand a flagged ruleshow_rule
Get detailed project metricsget_component_measures
Mark an issue as false positivechange_sonar_issue_status

If the user's intent is ambiguous, ask for the project key and the goal before proceeding.

Step 2: Quality Gate Monitoring

Use get_project_quality_gate_status to verify a project meets its quality standards.

Parameters:

  • projectKey (string) — Project key in SonarQube/SonarCloud
  • pullRequest (string, optional) — Pull request ID for PR-specific gate check
  • analysisId (string, optional) — Specific analysis ID

Note: There is no branch parameter on this tool. Without a pullRequest or analysisId, the tool returns the quality gate status for the default branch.

Pattern — Check default branch gate:

json
{
  "name": "get_project_quality_gate_status",
  "arguments": {
    "projectKey": "my-application"
  }
}

Pattern — Check PR gate before merge:

json
{
  "name": "get_project_quality_gate_status",
  "arguments": {
    "projectKey": "backend-service",
    "pullRequest": "456"
  }
}

Interpreting the response:

  • status: "OK" — Gate passed, safe to merge/deploy
  • status: "ERROR" — Gate failed; check conditions array for failing metrics
  • Each condition shows: metricKey, actualValue, errorThreshold, comparator

For more on metric keys, see references/metrics.md.

Step 3: Issue Discovery and Triaging

Use search_sonar_issues_in_projects to find and prioritize issues.

Parameters:

  • projects (array, optional) — List of project keys; omit to search all accessible projects
  • severities (array, optional) — Filter: BLOCKER, HIGH, MEDIUM, LOW, INFO
  • pullRequestId (string, optional) — Limit search to a specific PR
  • p (integer, optional) — Page number (default: 1)
  • ps (integer, optional) — Page size (default: 100, max: 500)

Pattern — Find blockers and critical issues:

json
{
  "name": "search_sonar_issues_in_projects",
  "arguments": {
    "projects": ["my-backend", "my-frontend"],
    "severities": ["BLOCKER", "HIGH"],
    "p": 1,
    "ps": 50
  }
}

Pattern — Search issues in a PR:

json
{
  "name": "search_sonar_issues_in_projects",
  "arguments": {
    "projects": ["my-service"],
    "pullRequestId": "123",
    "severities": ["HIGH", "MEDIUM"],
    "p": 1,
    "ps": 100
  }
}

Managing issues with change_sonar_issue_status:

Use this to mark false positives or accepted technical debt:

json
{
  "name": "change_sonar_issue_status",
  "arguments": {
    "key": "AY1234",
    "status": "falsepositive",
    "comment": "This pattern is safe in our context because..."
  }
}

Valid statuses: falsepositive (not a real issue), accept (acknowledged technical debt), reopen (reset to open)

Always present the list of issues to the user before changing their status. Never autonomously mark issues as false positives without explicit user confirmation.

Step 4: Pre-Push Analysis (Shift Left)

Use analyze_code_snippet to run SonarQube analysis on code before committing.

Parameters:

  • projectKey (string) — Project key for context
  • fileContent (string, required) — Full content of the file to analyze
  • language (string, optional) — Language hint for better accuracy
  • codeSnippet (string, optional) — Narrow results to a specific sub-range within fileContent

Supported languages: javascript, typescript, python, java, go, php, cs, cpp, kotlin, ruby, scala, swift

Pattern — Analyze TypeScript file before commit:

json
{
  "name": "analyze_code_snippet",
  "arguments": {
    "projectKey": "my-typescript-app",
    "fileContent": "async function fetchUser(id: string) {\n  const query = `SELECT * FROM users WHERE id = ${id}`;\n  return db.execute(query);\n}",
    "language": "typescript"
  }
}

Pattern — Analyze Python file:

json
{
  "name": "analyze_code_snippet",
  "arguments": {
    "projectKey": "my-python-service",
    "fileContent": "import pickle\n\ndef load_model(path):\n    with open(path, 'rb') as f:\n        return pickle.load(f)",
    "language": "python"
  }
}

Response interpretation:

  • Each issue includes: ruleKey, severity, clean code attribute, impact category, line number, quick fix availability
  • Address CRITICAL and HIGH severity issues before committing
  • Use show_rule with the ruleKey value for any unfamiliar rule
Show full SKILL.md (488 more words)Show less
Step 5: Rule Education

Use show_rule to understand why a rule exists and how to fix flagged code.

Parameters:

  • key (string) — Rule key in format <language>:<rule-id> (e.g., typescript:S1082, java:S2068)

Pattern — Get rule documentation:

json
{
  "name": "show_rule",
  "arguments": {
    "key": "typescript:S1082"
  }
}

Response includes: rule name, type, severity, full description, tags (e.g., cwe, owasp-a2), language, remediation effort estimate, code examples (non-compliant vs compliant).

Step 6: Get Component Measures

Use get_component_measures to retrieve detailed metrics for a project, directory, or file.

Parameters:

  • projectKey (string) — Project key in SonarQube/SonarCloud
  • pullRequest (string, optional) — PR ID for PR-scoped metrics
  • metricKeys (array) — List of metric keys to retrieve

Common metric keys: coverage, bugs, vulnerabilities, code_smells, complexity, cognitive_complexity, ncloc, duplicated_lines_density, new_coverage, new_bugs

Pattern — Project health dashboard:

json
{
  "name": "get_component_measures",
  "arguments": {
    "projectKey": "my-project-key",
    "metricKeys": ["coverage", "bugs", "vulnerabilities", "code_smells", "ncloc"]
  }
}

For full metric reference, see references/metrics.md.

Step 7: Present Results to User

After each tool call:

  • Summarize findings in human-readable form
  • Flag issues that require attention (BLOCKER, HIGH severity)
  • Propose next actions based on findings
  • Wait for user confirmation before taking remediation steps (e.g., changing issue status, modifying code)

Examples

Example 1: Pre-Merge Quality Gate Check

User request: "Check if the quality gate passes for project backend-api on PR #234"

json
{
  "name": "get_project_quality_gate_status",
  "arguments": {
    "projectKey": "backend-api",
    "pullRequest": "234"
  }
}

If gate fails: Extract failing conditions, present them to the user, then use search_sonar_issues_in_projects filtered by the same PR to show the actual issues.

Example 2: Shift-Left Analysis Before Push

User request: "Analyze this Go function before I push it"

json
{
  "name": "analyze_code_snippet",
  "arguments": {
    "projectKey": "my-go-service",
    "fileContent": "func handler(w http.ResponseWriter, r *http.Request) {\n  id := r.URL.Query().Get(\"id\")\n  query := fmt.Sprintf(\"SELECT * FROM orders WHERE id = %s\", id)\n  rows, _ := db.Query(query)\n  // ...\n}",
    "language": "go"
  }
}

Present findings → for each issue, optionally call show_rule with the ruleKey value to explain the fix.

Example 3: Triage BLOCKER Issues in a Project

User request: "Show me all blocker issues in payment-service"

json
{
  "name": "search_sonar_issues_in_projects",
  "arguments": {
    "projects": ["payment-service"],
    "severities": ["BLOCKER"],
    "p": 1,
    "ps": 50
  }
}

Group results by category (Security, Reliability, Maintainability) and present to user. Offer to call show_rule for unfamiliar rules.

Best Practices

  1. Environment Setup — Set credentials once per session; the MCP server automatically picks them up
  2. Always check quality gate before merge — Run get_project_quality_gate_status as part of any PR review workflow
  3. Shift left on security issues — Use analyze_code_snippet during development, not only in CI
  4. Prioritize by severity — Address BLOCKER and HIGH issues first; document decisions for MEDIUM and LOW
  5. Use show_rule for unfamiliar keys — Never dismiss a rule without understanding its intent
  6. Paginate large result sets — Use p and ps parameters; handle multi-page responses for complete coverage
  7. Never change issue status autonomously — Always present issues to the user and get explicit confirmation before calling change_sonar_issue_status
  8. Provide language hints — Specify language in analyze_code_snippet for more accurate analysis

Constraints and Warnings

  • MCP server must be configured and running; verify tool availability before use
  • analyze_code_snippet analyzes snippets in isolation — full project context may affect results in CI
  • Issue status changes (false positive, won't fix) require appropriate SonarQube permissions
  • SonarCloud and SonarQube Server APIs are mostly compatible but some features differ; check references/llm-context.md
  • Pagination is required for projects with many issues; check paging.total and paging.pageSize in the response to determine whether to iterate further pages
  • Quality gate status reflects the last completed analysis — trigger a new analysis if the code has changed

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/developer-kit-tools/skills/sonarqube-mcp of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/best-practices.md
  • references/llm-context.md
  • references/metrics.md
  • references/severity-levels.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Sonarqube MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonarqube MCP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonarqube MCP this skillgiuseppe-trisciuoglio/developer-kit357—~3.3kAutomated safety check: PassMIT
Suede MCP Release QAJasonColapietro/suede-creator-skills127—~2.1kAutomated safety check: PassMIT
Sonar CoverageSonarSource/sonarqube-agent-plugins111—~2.1kAutomated safety check: PassCustom licence
Pcb Designoaslananka/kicad-mcp-pro120—~1.5kAutomated safety check: PassMIT
Schematic Reviewoaslananka/kicad-mcp-pro120—~1.1kAutomated safety check: PassMIT
Sentry Issue Fixergenlayerlabs/genlayer-studio180—~2kAutomated safety check: PassMIT

Similar skills

  • Suede MCP Release QA

    JasonColapietro/suede-creator-skills

    Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.

    127 GitHub stars~2.1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Sonar Coverage

    SonarSource/sonarqube-agent-plugins

    Official

    Find files with low test coverage and inspect uncovered lines in a SonarQube project (project key optional when MCP integration already defines the default project)

    111 GitHub stars~2.1k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Pcb Design

    oaslananka/kicad-mcp-pro

    Safe KiCad PCB design assistance workflow using KiCad MCP board inspection, placement, routing, stackup, and quality-gate tools.

    120 GitHub stars~1.5k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Schematic Review

    oaslananka/kicad-mcp-pro

    KiCad MCP schematic inspection and review workflow using ERC, connectivity, symbol, net, power, readability, and quality-gate tools.

    120 GitHub stars~1.1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Sentry Issue Fixer

    genlayerlabs/genlayer-studio

    Fetch, analyze, fix Sentry issues, run tests, and create PRs

    180 GitHub stars~2k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Sonar Quality Gate

    SonarSource/sonarqube-agent-plugins

    Official

    Show SonarQube quality gate status for a project — pass/fail and each condition (metric key, threshold, actual value), plus worst-offender breakdowns.

    111 GitHub stars~4.1k tokensUpdated 3 days ago
    Testing & QAAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Questions about Sonarqube MCP

What does Sonarqube MCP do?

Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server. Sonarqube MCP is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server.

When should I use Sonarqube MCP?

Sonarqube MCP fits situations like: the user wants to check quality gates; search for Sonar issues; analyze code snippets before committing; understand SonarQube rules.

How do I install Sonarqube MCP in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a claude-code`. Or copy the skill folder (plugins/developer-kit-tools/skills/sonarqube-mcp in giuseppe-trisciuoglio/developer-kit) into .claude/skills/sonarqube-mcp in your project. Claude Code loads it when a task matches its description.

How do I install Sonarqube MCP in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a codex`. Or copy the skill folder (plugins/developer-kit-tools/skills/sonarqube-mcp in giuseppe-trisciuoglio/developer-kit) into .agents/skills/sonarqube-mcp in your project. Codex loads it when a task matches its description.

Can I use Sonarqube MCP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill sonarqube-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarqube-mcp, .gemini/skills/sonarqube-mcp, .github/skills/sonarqube-mcp and .opencode/skills/sonarqube-mcp in your project.

What does Sonarqube MCP need to run?

Going by SKILL.md and its folder, Sonarqube MCP needs credentials named SONARQUBE_TOKEN. Our summary lists: Python 3; Docker; A credential in SONARQUBE_TOKEN. Its frontmatter pre-approves these tools: Read.

Does Sonarqube MCP access the network?

SKILL.md names 2 domains. As links in the text: github.com and hub.docker.com. This is read from the text; nothing was executed.

Is Sonarqube MCP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sonarqube MCP use?

Sonarqube MCP is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sonarqube MCP use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.

What are the alternatives to Sonarqube MCP?

Skills that share tags, products or a category with Sonarqube MCP: Suede MCP Release QA (JasonColapietro/suede-creator-skills, 127 stars), Sonar Coverage (SonarSource/sonarqube-agent-plugins, 111 stars), Pcb Design (oaslananka/kicad-mcp-pro, 120 stars) and Schematic Review (oaslananka/kicad-mcp-pro, 120 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonarqube MCP?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.