Agent skill

Sonarjs

by managedcode in managedcode/dotnet-skills

Use SonarJS-derived rules in .NET repositories that ship JavaScript or TypeScript frontends and need deeper bug-risk, code-smell, or cognitive-complexity checks than a minimal ESLint baseline.

MITAuto-check passedDevelopment

Install Sonarjs

skills CLI
$ npx skills add managedcode/dotnet-skills --skill sonarjs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install managedcode/dotnet-skills sonarjs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/managedcode/dotnet-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/Tools/SonarJS/skills/sonarjs .claude/skills/sonarjs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonarjs
GitHub stars
486
Token cost
~1.6k tokens
SKILL.md length
695 words
Files
2
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

Use SonarJS-derived rules in .NET repositories that ship JavaScript or TypeScript frontends and need deeper bug-risk, code-smell, or cognitive-complexity checks than a minimal ESLint baseline.

  • Works in 7 steps: Decide the execution path first → For local work, treat SonarJS as an… → Keep the first rollout narrow → …
  • Eslint-plugin-sonarjs setups
  • SKILL.md covers Trigger On, Do Not Use For, Inputs and Workflow, plus 7 more sections
  • Calls rg, npm and npx

What it does

Sonarjs is an agent skill from managedcode/dotnet-skills. Use SonarJS-derived rules in .NET repositories that ship JavaScript or TypeScript frontends and need deeper bug-risk, code-smell, or cognitive-complexity checks than a minimal ESLint baseline. USE FOR: SonarQube, SonarCloud, or eslint-plugin-sonarjs setups; frontend code smells; cognitive complexity and deeper bug-risk rules. DO NOT USE FOR: lightweight base lint setups with no extra smell or complexity rules; teams that reject Sonar tooling. INVOKES: inspect the repository context, edit targeted files, and run…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `manifest.json`). Compatibility notes: Requires a .NET repository with JS or TS frontend assets; local developer loops normally use eslint-plugin-sonarjs, while full SonarQube or SonarCloud…

It sits in Development, covering Linting and formatting, Refactoring and Codebase knowledge for agents. It works with ESLint, .NET, JavaScript and TypeScript. The repository describes itself as: Installable .NET skill catalog and CLI for Codex, Claude Code, GitHub Copilot, and Gemini. The licence is MIT.

When your agent uses it

  • Eslint-plugin-sonarjs setups
  • Frontend code smells
  • Cognitive complexity and deeper bug-risk rules
  • : lightweight base lint setups with no extra smell

Example prompts

  • “/sonarjs”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Requires a .NET repository with JS or TS frontend assets; local developer loops normally use `eslint-plugin-sonarjs`, while full SonarQube or SonarCloud analysis should follow the repo's existing scanner pipeline and documented licensing posture.

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Decide the execution path first
  2. For local work, treat SonarJS as an ESLint extension rather than a standalone CLI.
  3. Keep the first rollout narrow
  4. Add rules to the existing ESLint command instead of inventing a parallel local lint entrypoint.
  5. If the repo already has SonarQube or SonarCloud, align local rule expectations with the server gate instead of maintaining two conflicting…
  6. Fix code or phase rules deliberately; do not hide the first rollout behind broad disables.
  7. Document licensing or hosting caveats before making Sonar-based tooling the default quality gate.

What it can do on your machine

Read from SKILL.md and the folder at commit 535dd55. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a .NET repository with JS or TS frontend assets; local developer loops normally use `eslint-plugin-sonarjs`, while full SonarQube or SonarCloud analysis should follow the repo's existing scanner pipeline and documented licensing posture.

    From compatibility in the SKILL.md frontmatter.

Context cost

Sonarjs loads about 1.6k tokens when it runs. Until then it costs about 150 tokens; SKILL.md has 695 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~150
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from managedcode/dotnet-skills at commit 535dd55, republished under its MIT licence (© managedcode). 695 words, ~1,579 tokens.

Download SKILL.mdSave it as .claude/skills/sonarjs/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
sonarjs
description
Use SonarJS-derived rules in .NET repositories that ship JavaScript or TypeScript frontends and need deeper bug-risk, code-smell, or cognitive-complexity checks than a minimal ESLint baseline. USE FOR: SonarQube, SonarCloud, or eslint-plugin-sonarjs setups; frontend code smells; cognitive complexity and deeper bug-risk rules. DO NOT USE FOR: lightweight base lint setups with no extra smell or complexity rules; teams that reject Sonar tooling. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
compatibility
Requires a .NET repository with JS or TS frontend assets; local developer loops normally use `eslint-plugin-sonarjs`, while full SonarQube or SonarCloud analysis should follow the repo's existing scanner pipeline and documented licensing posture.

SonarJS Rules for Frontend Assets in .NET Repositories

Trigger On

  • the repo already uses SonarQube, SonarCloud, or eslint-plugin-sonarjs
  • the user asks for frontend code smells, cognitive complexity limits, or deeper bug-risk rules beyond base ESLint
  • maintainability and reliability findings on JS or TS code should become a review or CI gate

Do Not Use For

  • repos that want only a lightweight base lint setup with no extra smell or complexity rules
  • teams that reject SonarQube, SonarCloud, or source-available SonarJS-derived tooling as a default gate
  • cases where the problem is runtime page quality rather than source-level maintainability

Inputs

  • the nearest AGENTS.md
  • package.json
  • existing ESLint config
  • any SonarQube, SonarCloud, or scanner config already present in CI
mermaid
flowchart LR
  A["Need Sonar-style checks in a .NET repo frontend"] --> B{"Local developer loop or existing server gate?"}
  B -->|Local| C["Install eslint-plugin-sonarjs"]
  C --> D["Run through the normal eslint command"]
  B -->|Existing SonarQube or SonarCloud gate| E["Keep full analysis in the existing scanner pipeline"]
  D --> F["Phase rules and fix code"]
  E --> F

Workflow

  1. Decide the execution path first:
    • local developer loop through eslint-plugin-sonarjs
    • server-side analysis through an already adopted SonarQube or SonarCloud pipeline
  2. For local work, treat SonarJS as an ESLint extension rather than a standalone CLI.
  3. Keep the first rollout narrow:
    • bug-prone rules
    • cognitive complexity
    • duplicated branching or suspicious control flow
  4. Add rules to the existing ESLint command instead of inventing a parallel local lint entrypoint.
  5. If the repo already has SonarQube or SonarCloud, align local rule expectations with the server gate instead of maintaining two conflicting policies.
  6. Fix code or phase rules deliberately; do not hide the first rollout behind broad disables.
  7. Document licensing or hosting caveats before making Sonar-based tooling the default quality gate.

Current Upstream Notes

  • SonarJS 13.8 adds guidance to prefer native APIs over Axios utility methods and retryable Cypress assertions. It also fixes false positives for deferred Promise chains, ordinary class members, and Deno.test declarations, and narrows related test-file and form analysis heuristics.
  • Re-run server analysis before preserving suppressions, and review new findings as behavior-specific guidance rather than enabling every new rule blindly. Self-hosted builds now require JDK 21 rather than JDK 17.

Bootstrap When Missing

  1. Detect current state:
    • rg --files -g 'package.json' -g 'eslint.config.*' -g '.eslintrc*'
    • rg -n '"eslint-plugin-sonarjs"|"sonar"|"sonarqube"|"sonarcloud"' .
  2. Prefer the local ESLint-plugin path for developer workflows:
    • npm install --save-dev eslint-plugin-sonarjs
  3. Add the plugin and selected rules to the checked-in ESLint config.
  4. Verify with the repo's normal lint entrypoint, for example:
    • npx eslint .
  5. If the repo already uses SonarQube or SonarCloud, keep the full analysis in that existing CI path instead of inventing a new local scanner flow.
  6. Return status: configured if SonarJS-derived checks now have explicit ownership, or status: improved if an existing setup was tightened.
  7. Return status: not_applicable when the repo explicitly chooses a purely OSS lint baseline without Sonar-based extensions.
Show full SKILL.md (269 more words)Show less

Handle Failures

  • There is no separate local sonarjs CLI from this repo; local developer use should go through ESLint with eslint-plugin-sonarjs.
  • Plugin-load failures usually mean the ESLint config does not match the installed plugin version or plugin registration syntax.
  • If the first rollout produces too many smells, phase rule adoption instead of disabling the plugin wholesale.
  • If SonarQube or SonarCloud disagrees with local lint output, treat the server gate as the source of truth and align the local config deliberately.

Deliver

  • explicit SonarJS-derived rule ownership
  • a clear split between local ESLint-based use and any existing server-side Sonar pipeline
  • documented rollout scope and caveats

Validate

  • local developer commands still use the repo's standard ESLint entrypoint
  • Sonar-based rules are not treated as a standalone local CLI when none exists
  • licensing or hosting caveats are documented before broad adoption
  • findings are actionable and phased instead of silently suppressed

Ralph Loop

  1. Plan: analyze current state, target outcome, constraints, and risks.
  2. Execute one step and produce a concrete delta.
  3. Review the result and capture findings.
  4. Apply fixes in small batches and rerun checks.
  5. Update the plan after each iteration.
  6. Repeat until outcomes are acceptable.
  7. If a dependency is missing, bootstrap it or return status: not_applicable with a reason.
Required Result Format
  • status: complete | clean | improved | configured | not_applicable | blocked
  • plan: concise plan and current step
  • actions_taken: concrete changes made
  • verification: commands, checks, or review evidence
  • remaining: unresolved items or none

Example Requests

  • "Add SonarJS rules to the existing ESLint setup."
  • "Use cognitive complexity checks on the frontend."
  • "Explain whether we should use the ESLint plugin or SonarQube here."

© managedcode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in catalog/Tools/SonarJS/skills/sonarjs of managedcode/dotnet-skills.

  • SKILL.md
  • manifest.json

Open the folder on GitHubat commit 535dd55

Compare with similar skills

Sonarjs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonarjs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonarjs this skillmanagedcode/dotnet-skills486—~1.6kAutomated safety check: PassMIT
Ultraciteagustinusnathaniel/nextarter-tailwind1252 repos~1.2kAutomated safety check: PassMIT
Code Qualityredis/RedisInsight8.9k—~1.2kAutomated safety check: PassCustom licence
Port Ruleweb-infra-dev/rslint460—~1.7kAutomated safety check: PassMIT
Migrate OxlintAsvarox/allkaraoke2614 repos~2.5kAutomated safety check: PassNone
Git HooksProrise-cool/Claude-Code-Multi-Agent305—~3.6kAutomated safety check: NotesNone

Similar skills

  • Ultracite

    agustinusnathaniel/nextarter-tailwind

    Ultracite is a zero-config linting and formatting preset for JavaScript/TypeScript projects.

    125 GitHub starsUsed in 2 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Code Quality

    redis/RedisInsight

    Official

    Code-quality standards for RedisInsight: TypeScript strictness, naming conventions (camelCase, PascalCase, UPPERSNAKECASE), linting rules, no any without reason, no !important in styles, and…

    8.9k GitHub stars~1.2k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Port Rule

    web-infra-dev/rslint

    Port a new ESLint core or plugin rule to rslint, including explicitly requested batches.

    460 GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Migrate Oxlint

    Asvarox/allkaraoke

    Guide for migrating a project from ESLint to Oxlint. An agent skill from Asvarox/allkaraoke.

    261 GitHub starsUsed in 4 repos~2.5k tokens
    DevelopmentAuto-check passed
  • Git Hooks

    Prorise-cool/Claude-Code-Multi-Agent

    Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.

    305 GitHub stars~3.6k tokensUpdated 22 days ago
    DevelopmentAuto-check: notes
  • Migrate or upgrade TypeScript tooling in the Phoenix monorepo.

    12k GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed

More from managedcode/dotnet-skills

All 81 skills in this repo
  • Analyzer Config

    managedcode/dotnet-skills

    Use a repo-root .editorconfig to configure free .NET analyzer and style rules.

    486 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Archunitnet

    managedcode/dotnet-skills

    Use the open-source free ArchUnitNET library for architecture rules in .NET tests.

    486 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Aspire

    managedcode/dotnet-skills

    Build, upgrade, and operate Aspire 13.5.x C or TypeScript application hosts with the current CLI, AppHost, ServiceDefaults, integrations, dashboard, testing, MCP, and deployment patterns for…

    486 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Aspnet Core

    managedcode/dotnet-skills

    Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET.

    486 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Asynkron Profiler

    managedcode/dotnet-skills

    Use the open-source free Asynkron.Profiler dotnet tool for CLI-first CPU, allocation, exception, contention, and heap profiling of .NET commands or existing trace artifacts.

    486 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Azure Functions

    managedcode/dotnet-skills

    Build, review, or migrate Azure Functions in .NET with correct execution model, isolated worker setup, bindings, DI, and Durable Functions patterns.

    486 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Questions about Sonarjs

What does Sonarjs do?

Use SonarJS-derived rules in .NET repositories that ship JavaScript or TypeScript frontends and need deeper bug-risk, code-smell, or cognitive-complexity checks than a minimal ESLint baseline. Sonarjs is an agent skill from managedcode/dotnet-skills.NET repositories that ship JavaScript or TypeScript frontends and need deeper bug-risk, code-smell, or cognitive-complexity checks than a minimal ESLint baseline.

When should I use Sonarjs?

Sonarjs fits situations like: eslint-plugin-sonarjs setups; frontend code smells; cognitive complexity and deeper bug-risk rules; : lightweight base lint setups with no extra smell.

How do I install Sonarjs in Claude Code?

Run `npx skills add managedcode/dotnet-skills --skill sonarjs -a claude-code`. Or copy the skill folder (catalog/Tools/SonarJS/skills/sonarjs in managedcode/dotnet-skills) into .claude/skills/sonarjs in your project. Claude Code loads it when a task matches its description.

How do I install Sonarjs in Codex?

Run `npx skills add managedcode/dotnet-skills --skill sonarjs -a codex`. Or copy the skill folder (catalog/Tools/SonarJS/skills/sonarjs in managedcode/dotnet-skills) into .agents/skills/sonarjs in your project. Codex loads it when a task matches its description.

Can I use Sonarjs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add managedcode/dotnet-skills --skill sonarjs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonarjs, .gemini/skills/sonarjs, .github/skills/sonarjs and .opencode/skills/sonarjs in your project.

What does Sonarjs need to run?

Going by SKILL.md and its folder, Sonarjs needs the command-line tools its instructions call (rg, npm and npx). Our summary lists: Node.js. Compatibility (from SKILL.md): Requires a .NET repository with JS or TS frontend assets; local developer loops normally use `eslint-plugin-sonarjs`, while full SonarQube or SonarCloud analysis should follow the repo's existing scanner pipeline and documented licensing posture..

Does Sonarjs access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sonarjs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sonarjs use?

Sonarjs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sonarjs use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sonarjs?

Skills that share tags, products or a category with Sonarjs: Ultracite (agustinusnathaniel/nextarter-tailwind, 125 stars), Code Quality (redis/RedisInsight, 8.9k stars), Port Rule (web-infra-dev/rslint, 460 stars) and Migrate Oxlint (Asvarox/allkaraoke, 261 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonarjs?

managedcode (a GitHub organization) maintains it in managedcode/dotnet-skills, which has 486 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 7, 2026.

Source: managedcode/dotnet-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.