Agent skill

Sonarqube Analysis

by hbmartin in hbmartin/graphviz2drawio

Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials.

GPL-3.0Auto-check: notesTesting & QA

Install Sonarqube Analysis

skills CLI
$ npx skills add hbmartin/graphviz2drawio --skill sonarqube-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hbmartin/graphviz2drawio sonarqube-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hbmartin/graphviz2drawio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/sonarqube-analysis .claude/skills/sonarqube-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonarqube-analysis
GitHub stars
275
Token cost
~508 tokens
SKILL.md length
150 words
Files
3 (incl. scripts)
Skills in repo
3
Repo updated
First seen
Licence
GPL-3.0

At a glance

Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials.

  • Works in 5 steps: Load Sonar settings from the repo .env… → Prefer the bundled script → If the user asks for a focused slice,… → …
  • The user asks to inspect
  • SKILL.md covers Workflow, Safety and Expected .env
  • Runs Python scripts from its folder; calls python3; reaches sonarcloud.io; needs SONAR_TOKEN and SONAR_PROJECT_KEY

What it does

Sonarqube Analysis is an agent skill from hbmartin/graphviz2drawio. Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials. Use when the user asks to inspect, summarize, triage, prioritize, or fix SonarQube/SonarCloud issues, quality gate results, security hotspots, vulnerabilities, bugs, code smells, or new-code findings.

Its SKILL.md is about 510 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/sonar_report.py`).

It sits in Testing & QA, covering Quality gates and Refactoring. It works with draw.io. The repository describes itself as: Convert graphviz (dot) files to draw.io / lucid (mxGraph) format. Beautiful and editable graphs in your favorite editor. The licence is GPL-3.0.

When your agent uses it

  • The user asks to inspect
  • Fix SonarQube/SonarCloud issues
  • Quality gate results
  • Security hotspots

Example prompts

  • “/sonarqube-analysis”

Requirements

  • Python 3
  • A credential in SONAR_TOKEN
  • A credential in SONAR_PROJECT_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Load Sonar settings from the repo .env without printing secrets.
  2. Prefer the bundled script
  3. If the user asks for a focused slice, pass one or more flags
  4. Summarize findings in this order
  5. For fix work, inspect the local source before editing. Separate likely real defects from generated-code noise and false positives.

What it can do on your machine

Read from SKILL.md and the folder at commit 96c691c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • sonarcloud.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN
    • SONAR_PROJECT_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sonarqube Analysis loads about 508 tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 150 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~508

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    findings for this repository using local .env credentials. Use when the user asks to inspect, summarize, triage, priorit
  • NoteMentions a .env fileSKILL.md:10
    1. Load Sonar settings from the repo `.env` without printing secrets.
  • NoteMentions a .env fileSKILL.md:11
    arCloud project and branch specified in `.env`.
  • NoteMentions a .env fileSKILL.md:38
    - Never print `SONAR_TOKEN` or raw `.env` contents.
  • NoteMentions a .env fileSKILL.md:43
    ## Expected `.env`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from hbmartin/graphviz2drawio at commit 96c691c, republished under its GPL-3.0 licence (© hbmartin). 150 words, ~508 tokens.

Download SKILL.mdSave it as .claude/skills/sonarqube-analysis/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
sonarqube-analysis
description
Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials. Use when the user asks to inspect, summarize, triage, prioritize, or fix SonarQube/SonarCloud issues, quality gate results, security hotspots, vulnerabilities, bugs, code smells, or new-code findings.

SonarQube Analysis

Workflow

  1. Load Sonar settings from the repo .env without printing secrets. The script uses the SonarCloud project and branch specified in .env.

  2. Prefer the bundled script:

    bash
    python3 .codex/skills/sonarqube-analysis/scripts/sonar_report.py --format markdown
  3. If the user asks for a focused slice, pass one or more flags:

    bash
    python3 .codex/skills/sonarqube-analysis/scripts/sonar_report.py --bugs --security
    python3 .codex/skills/sonarqube-analysis/scripts/sonar_report.py --new-code
    python3 .codex/skills/sonarqube-analysis/scripts/sonar_report.py --branch main --top 20
    python3 .codex/skills/sonarqube-analysis/scripts/sonar_report.py --project your-org_your-project
  4. Summarize findings in this order:

    • quality gate and latest analysis date
    • vulnerabilities, bugs, blockers, and security hotspots
    • new-code findings
    • largest maintainability clusters by rule/file
    • likely false positives/report hygiene
  5. For fix work, inspect the local source before editing. Separate likely real defects from generated-code noise and false positives.

Safety

  • Never print SONAR_TOKEN or raw .env contents.
  • Ask before making live Sonar changes such as marking false positives, accepting issues, or changing project settings.
  • Treat sonar.exclusions as a multi-value setting when using the Sonar API.
  • Use local file references in final answers when a finding maps to this checkout.

Expected .env

The script expects these keys:

bash
SONAR_HOST_URL=https://sonarcloud.io
SONAR_ORG=your-org
SONAR_PROJECT_KEY=your-org_your-project
SONAR_BRANCH=main
SONAR_TOKEN=...

© hbmartin, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .codex/skills/sonarqube-analysis of hbmartin/graphviz2drawio.

  • SKILL.md
  • agents/openai.yaml
  • scripts/sonar_report.py

Open the folder on GitHubat commit 96c691c

Compare with similar skills

Sonarqube Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonarqube Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonarqube Analysis this skillhbmartin/graphviz2drawio275—~508Automated safety check: NotesGPL-3.0
Triage Sonarqubenetdata/netdata81k—~2.8kAutomated safety check: NotesGPL-3.0
Code SolvingHoangTheQuyen/think-better122—~3.7kAutomated safety check: PassMIT
Refactor To Rulesopenfootmanager/openfootmanager1.1k—~1.3kAutomated safety check: NotesGPL-3.0
AI Development Guideshinpr/claude-code-workflows694—~3.9kAutomated safety check: PassMIT
Ccg Workflowfengshao1227/ccg-workflow5.9k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Testing & QAAuto-check: notes
  • Code Solving

    HoangTheQuyen/think-better

    Structured coding workflow for non-trivial code work: debug, build features, refactor, optimize, migrate and review code through 7 steps with evidence-based quality gates.

    122 GitHub stars~3.7k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Refactor To Rules

    openfootmanager/openfootmanager

    Decompose OpenFoot Manager code by responsibility when a quality gate is red, a reviewer requests a split or a refactor is authorized.

    1.1k GitHub stars~1.3k tokensUpdated today
    Testing & QAAuto-check: notes
  • AI Development Guide

    shinpr/claude-code-workflows

    Applies language-agnostic and backend technical decision criteria, anti-pattern detection, debugging, and quality gates.

    694 GitHub stars~3.9k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Ccg Workflow

    fengshao1227/ccg-workflow

    How to run a non-trivial change end to end with the CCG role tools (ccganalyze / ccgdesign / ccgbuild / ccgdebug / ccgoptimize / ccgreview / ccgtest) and the verify- quality gates.

    5.9k GitHub stars~2.3k tokensUpdated 24 days ago
    Testing & QAAuto-check passed
  • Sonarcloud Review

    lucasvieirasilva/nx-plugins

    Fetches and triages SonarCloud findings (issues, security hotspots, quality gate) for the current pull request or branch of this repository via the SonarCloud Web API, summarizes them in a markdown…

    153 GitHub stars~2.7k tokensUpdated 11 days ago
    DevelopmentAuto-check: notes

More from hbmartin/graphviz2drawio

  • Compare Render

    hbmartin/graphviz2drawio

    Visually verify graphviz2drawio conversion fidelity by rendering a graphviz source side-by-side as a native graphviz PNG and a converted draw.io PNG, then reading both images to compare.

    275 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Compare Render

    hbmartin/graphviz2drawio

    Visually verify graphviz2drawio conversion fidelity by rendering a Graphviz source as both native Graphviz PNG and converted draw.io PNG, then inspecting the images.

    275 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Sonarqube Analysis

What does Sonarqube Analysis do?

Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials. Sonarqube Analysis is an agent skill from hbmartin/graphviz2drawio.env credentials.

When should I use Sonarqube Analysis?

Sonarqube Analysis fits situations like: the user asks to inspect; fix SonarQube/SonarCloud issues; quality gate results; security hotspots.

How do I install Sonarqube Analysis in Claude Code?

Run `npx skills add hbmartin/graphviz2drawio --skill sonarqube-analysis -a claude-code`. Or copy the skill folder (.codex/skills/sonarqube-analysis in hbmartin/graphviz2drawio) into .claude/skills/sonarqube-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Sonarqube Analysis in Codex?

Run `npx skills add hbmartin/graphviz2drawio --skill sonarqube-analysis -a codex`. Or copy the skill folder (.codex/skills/sonarqube-analysis in hbmartin/graphviz2drawio) into .agents/skills/sonarqube-analysis in your project. Codex loads it when a task matches its description.

Can I use Sonarqube Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hbmartin/graphviz2drawio --skill sonarqube-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarqube-analysis, .gemini/skills/sonarqube-analysis, .github/skills/sonarqube-analysis and .opencode/skills/sonarqube-analysis in your project.

What does Sonarqube Analysis need to run?

Going by SKILL.md and its folder, Sonarqube Analysis needs Python for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named SONAR_TOKEN and SONAR_PROJECT_KEY. Our summary lists: Python 3; A credential in SONAR_TOKEN; A credential in SONAR_PROJECT_KEY.

Does Sonarqube Analysis access the network?

SKILL.md names 1 domain. In commands or code: sonarcloud.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sonarqube Analysis safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sonarqube Analysis use?

Sonarqube Analysis is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sonarqube Analysis use?

About 508 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sonarqube Analysis?

Skills that share tags, products or a category with Sonarqube Analysis: Triage Sonarqube (netdata/netdata, 81k stars), Code Solving (HoangTheQuyen/think-better, 122 stars), Refactor To Rules (openfootmanager/openfootmanager, 1.1k stars) and AI Development Guide (shinpr/claude-code-workflows, 694 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonarqube Analysis?

hbmartin (a GitHub user) maintains it in hbmartin/graphviz2drawio, which has 275 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on August 7, 2026.

Source: hbmartin/graphviz2drawio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.