Agent skill

Triage Sonarqube

by netdata in netdata/netdata

Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

GPL-3.0Auto-check: notesTesting & QA

Install Triage Sonarqube

skills CLI
$ npx skills add netdata/netdata --skill triage-sonarqube -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata triage-sonarqube --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/triage-sonarqube .claude/skills/triage-sonarqube && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triage-sonarqube
GitHub stars
81k
Token cost
~2.8k tokens
SKILL.md length
1,187 words
Files
6 (incl. scripts)
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

  • Works in 4 steps: see what's open → search for specific rule's findings → triage → …
  • SonarQube/SonarCloud findings
  • SKILL.md covers MANDATORY — keep this skill…, Setup, Triage decision matrix and ASCII-only comments —…, plus 5 more sections
  • Runs Shell scripts from its folder; calls bash and jq; reaches sonarcloud.io; needs SONAR_TOKEN and ISSUE_KEY

What it does

Triage Sonarqube is an agent skill from netdata/netdata. Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers. Use for SonarQube/SonarCloud findings, code smells, vulnerabilities, and quality-gate evidence. Supplied evidence needs no live query; per-finding writes and project-wide policy changes have distinct scopes.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `how-tos/INDEX.md`, `how-tos/triage-pr-duplication-gate.md` and `scripts/_lib.sh`).

It sits in Testing & QA, covering Refactoring and Quality gates. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • SonarQube/SonarCloud findings
  • Vulnerabilities
  • Quality-gate evidence

Example prompts

  • “/triage-sonarqube”

Requirements

  • Python 3
  • A Bash shell
  • Docker
  • A credential in SONAR_TOKEN
  • A credential in ISSUE_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. see what's open
  2. search for specific rule's findings
  3. triage
  4. dry runs

What it can do on your machine

Read from SKILL.md and the folder at commit a7f3cf9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • sonarcloud.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN
    • ISSUE_KEY
    • HOTSPOT_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triage Sonarqube loads about 2.8k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 1,187 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:18
    Scripts use the project configured in `.env` and keep audit artifacts under `<repo>/.local/`. Read only the sections
  • NoteMentions a .env fileSKILL.md:36
    ### .env entries
  • NoteMentions a .env fileSKILL.md:189
    | Missing `.env` for a public PR query   | Try `https://sonarcloud.io/api/issues/search` with `componentKeys`, `pullRequ

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from netdata/netdata at commit a7f3cf9, republished under its GPL-3.0 licence (© netdata). 1,187 words, ~2,827 tokens.

Download SKILL.mdSave it as .claude/skills/triage-sonarqube/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
triage-sonarqube
description
Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers. Use for SonarQube/SonarCloud findings, code smells, vulnerabilities, and quality-gate evidence. Supplied evidence needs no live query; per-finding writes and project-wide policy changes have distinct scopes.

SonarCloud triage skill

Use the requested operation to select the workflow. Loading this skill does not authorize remote transitions, comments, risk acceptance or changes to analysis policy.

TaskRoute
Review supplied findings or helper changesInspect the provided evidence and affected source; use the decision matrix as review criteria without credential setup or live requests
Inspect current findingsSearch only the requested project/PR/rule scope with configured credentials; preserve current source and analysis provenance
Apply authorized triageVerify each finding and its classification, then use the selected-key commands below
Change a whole rule family or project policyEstablish evidence and authorization for that complete scope before applying the family/profile procedure

Scripts use the project configured in .env and keep audit artifacts under <repo>/.local/. Read only the sections needed for the task; ordinary finding review does not require profile configuration.

MANDATORY — keep this skill alive

Capture timing and authorization for operational discoveries follow AGENTS.md#knowledge-capture.

Examples of things to capture:

  • New rule with a known FP pattern (and the exact comment to use)
  • A bulk-FP family that's safe to apply project-wide
  • A SonarCloud API quirk (rate limits, undocumented response shapes)
  • A new path/issue exclusion that's safer than per-finding marking

Setup

Setup is for live helper execution. Reuse configured credentials through the helper; never ask for tokens in the conversation. Offline evidence review does not need setup.

.env entries
bash
# SonarCloud
SONAR_TOKEN='<paste your token from https://sonarcloud.io/account/security>'
SONAR_HOST_URL=https://sonarcloud.io
SONAR_PROJECT=<project_key, e.g. netdata_netdata>
SONAR_ORG=<organization_key, e.g. netdata>

The token is used as HTTP Basic auth username with empty password: -u "$SONAR_TOKEN:" (note the trailing colon).

No browser tab is required for token-based auth. Tokens can expire or be revoked; verify access when executing.

Triage decision matrix

Issues (Bug, Vulnerability, Code Smell)
DecisionAPI transitionWhen to use
ConfirmconfirmSonar is right, we're going to fix it
Won't FixwontfixReal but acceptable — won't fix (e.g., legacy code being deleted)
False PositivefalsepositiveSonar is wrong (guard exists, unreachable, tool model error)
Security Hotspots

Hotspots have a separate state machine. They go from TO_REVIEW to REVIEWED with one of three resolutions:

ResolutionWhen to use
SAFEHotspot reviewed, code is fine as-is (no risk in context)
ACKNOWLEDGEDRisk understood, no immediate action — leave for future review
FIXEDHotspot reviewed and the code was changed to remove the risk

ASCII-only comments — non-negotiable

The helpers enforce ASCII-only comments before the network round-trip. This preserves a workaround for observed 403 challenges with non-ASCII bodies; it does not establish a universal current Cloudflare rule.

  • Use -- instead of em-dash (U+2014).
  • Use straight quotes " ' instead of smart quotes.

Workflow

Step 1 — see what's open
bash .agents/skills/triage-sonarqube/scripts/sonar-search.sh summary

Prints per-rule counts of open issues and hotspots. Use volume to prioritize inspection. A count or shared rule ID is not evidence that every finding is false positive, safe, or covered by the same exclusion.

Step 2 — search for specific rule's findings

Issues:

bash .agents/skills/triage-sonarqube/scripts/sonar-search.sh issues --rule cpp:S5827

Hotspots:

sh
bash .agents/skills/triage-sonarqube/scripts/sonar-search.sh hotspots --status=TO_REVIEW \
  | jq '.hotspots[] | select(.ruleKey=="c:S5443")'
Step 3 — triage

Before writing, verify the selected finding against reachable code, its current state and the matrix above. Record why the classification fits; FIXED requires the relevant code change. A request to inspect or review remains read-only. Existing authorization to apply the verified decisions persists; do not add another approval round for routine execution.

Single finding
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh fp     <ISSUE_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh wontfix <ISSUE_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh confirm <ISSUE_KEY> "<COMMENT>"

bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh safe  <HOTSPOT_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh ack   <HOTSPOT_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh fixed <HOTSPOT_KEY> "<COMMENT>"
Family mode (every open finding for a rule)
sh
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh family-fp   <RULE_ID> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh family-safe <RULE_ID> "<COMMENT>"

Prefer single-key commands for a reviewed subset. Family mode re-enumerates every currently open finding for the rule; it cannot express a selected path or evidence subset. Use it only when the evidence and user authorization cover that entire current set. Otherwise apply the already verified keys individually.

Family mode prints matched keys and prompts unless SONAR_MARK_YES=1 is set. That variable skips the helper prompt; it does not grant user authorization or extend it to newly discovered findings.

Step 4 — dry runs
SONAR_DRY_RUN=1 bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh fp KEY "Comment"

In dry-run mode, write API calls (mark issues, change hotspot status, add comments) are printed but not executed. Read API calls (issue search, hotspot search used to enumerate findings in family mode) still run -- otherwise family mode could not show what it would have acted on.

What this skill does NOT do

These are separate project-policy operations, not effects of per-finding triage. Perform them only when that scope is authorized:

  • Disable rules: the API offers api/qualityprofiles/deactivate_rule; the SonarCloud UI also exposes Quality Profiles.
  • Configure issue exclusions: use Project Settings -> Analysis Scope -> Issue Exclusions in the UI.
  • Rule-tuning audit: when you want a per-rule KEEP/DISABLE/NARROW decision log, document that separately (it's project-wide policy, not per-finding triage).
Show full SKILL.md (466 more words)Show less

Project-wide quality profile / exclusion configuration

Effective profile lookup:

GET /api/qualityprofiles/search?project=$SONAR_PROJECT&organization=$SONAR_ORG

Before an authorized project-wide change, inspect the effective profile, ownership, inheritance and other projects using it. Reuse an appropriate editable profile when the approved scope covers its consumers. If the inherited profile cannot be edited or its other consumers must remain unaffected, the API supports copying it (api/qualityprofiles/copy), editing the copy, and assigning this project (api/qualityprofiles/add_project). Verify the resulting effective profile; do not create a fresh copy automatically on every run.

SonarCloud language keys include: c, cpp, go, javascript, py, shell, plsql, docker, css, ipynb, php (and others depending on the project). Note the rule-id namespaces in api/issues/search results may differ from the language keys -- e.g. shell rules use the shelldre: prefix, Go rules can use either go: or godre: depending on which analyzer fired -- so the language argument to qualityprofile APIs is the SHORT key (shell, go), not the rule-namespace prefix.

Keep a record of profile decisions in a project-local doc under .local/audits/sonarqube/.

Failure modes — quick diagnosis

SymptomLikely cause
HTTP 401 / 403 with HTML bodyToken wrong/expired, or Cloudflare blocking non-ASCII
Missing .env for a public PR queryTry https://sonarcloud.io/api/issues/search with componentKeys, pullRequest, sinceLeakPeriod=true, and statuses=OPEN,CONFIRMED; anonymous reads have worked for public projects, but availability must be checked; failure is an evidence gap.
Token works for issues but not hotspotsHotspot endpoints have separate auth checks — token must have Browse permission
Family-mode appears to stop at 500Outdated -- sonar-mark.sh family-mode now paginates transparently via sq_paginate. If you still see truncation, check sq_paginate's array-key recognition list.
falsepositive transition rejectedCheck current state, available transitions and permissions; do not assume a previously supported transition is still available
Hotspot transition rejectedRe-check current state, available resolutions and permissions before retry

Recurring tips

  • For Python CLI injection findings, trace the actual entrypoint and validator. An analyzer may label argparse.parse_args() as HTTP input while overlooking choices= validation. Check enum-derived flags, absolute file arguments and operator-selected executables separately. shlex.join() used only in a printed diagnostic or exception message is display text, not execution. Verify each source/sink before classification; this pattern does not justify marking a whole rule family false positive.
  • api/issues/search is paged at ps=500 max. The sq_paginate helper in _lib.sh walks every page until paging.total; use it from any new script instead of re-implementing the loop.
  • PR new-code measures returned by api/measures/component_tree are stored under measures[].periods[0].value, not measures[].value. This matters for quality-gate metrics such as new_duplicated_lines, new_duplicated_lines_density, and new_lines.
  • Hotspot ruleKey filtering is client-side (search only filters by status/project), so the family-mode helper does it with jq.
  • An issue may be transitioned only between certain states; if you get "Cannot do transition from STATUS X to Y", inspect its current state and available transitions before retrying.
  • SONAR_DRY_RUN=1 is the right knob when iterating on comments before committing to a bulk operation.

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in .agents/skills/triage-sonarqube of netdata/netdata.

  • SKILL.md
  • how-tos/INDEX.md
  • how-tos/triage-pr-duplication-gate.md
  • scripts/_lib.sh
  • scripts/sonar-mark.sh
  • scripts/sonar-search.sh

Open the folder on GitHubat commit a7f3cf9

Compare with similar skills

Triage Sonarqube next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triage Sonarqube compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triage Sonarqube this skillnetdata/netdata81k—~2.8kAutomated safety check: NotesGPL-3.0
Sonarqube Analysishbmartin/graphviz2drawio275—~508Automated safety check: NotesGPL-3.0
Code SolvingHoangTheQuyen/think-better122—~3.7kAutomated safety check: PassMIT
AI Development Guideshinpr/claude-code-workflows693—~3.9kAutomated safety check: PassMIT
Ccg Workflowfengshao1227/ccg-workflow5.9k—~2.3kAutomated safety check: PassMIT
Sonarcloud Reviewlucasvieirasilva/nx-plugins153—~2.7kAutomated safety check: NotesMIT

Similar skills

  • Sonarqube Analysis

    hbmartin/graphviz2drawio

    Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials.

    275 GitHub stars~508 tokensUpdated 2 mo ago
    Testing & QAAuto-check: notes
  • Code Solving

    HoangTheQuyen/think-better

    Structured coding workflow for non-trivial code work: debug, build features, refactor, optimize, migrate and review code through 7 steps with evidence-based quality gates.

    122 GitHub stars~3.7k tokensUpdated today
    Testing & QAAuto-check passed
  • AI Development Guide

    shinpr/claude-code-workflows

    Applies language-agnostic and backend technical decision criteria, anti-pattern detection, debugging, and quality gates.

    693 GitHub stars~3.9k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Ccg Workflow

    fengshao1227/ccg-workflow

    How to run a non-trivial change end to end with the CCG role tools (ccganalyze / ccgdesign / ccgbuild / ccgdebug / ccgoptimize / ccgreview / ccgtest) and the verify- quality gates.

    5.9k GitHub stars~2.3k tokensUpdated 24 days ago
    Testing & QAAuto-check passed
  • Sonarcloud Review

    lucasvieirasilva/nx-plugins

    Fetches and triages SonarCloud findings (issues, security hotspots, quality gate) for the current pull request or branch of this repository via the SonarCloud Web API, summarizes them in a markdown…

    153 GitHub stars~2.7k tokensUpdated 11 days ago
    DevelopmentAuto-check: notes
  • Developing Marchat

    Cod-e-Codes/marchat

    Implements and refactors marchat Go code with project toolchain and quality gates.

    137 GitHub stars~870 tokensUpdated 6 days ago
    Testing & QAAuto-check passed

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Codacy

    netdata/netdata

    Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

    81k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Triage Coverity

    netdata/netdata

    Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

    81k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Create, review or validate Netdata Prometheus chart profiles, exporter dashboard design, collection policy and stock semantic proofs.

    81k GitHub stars~4.7k tokensUpdated today
    Auto-check passed

Questions about Triage Sonarqube

What does Triage Sonarqube do?

Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers. Triage Sonarqube is an agent skill from netdata/netdata. Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

When should I use Triage Sonarqube?

Triage Sonarqube fits situations like: sonarQube/SonarCloud findings; vulnerabilities; quality-gate evidence.

How do I install Triage Sonarqube in Claude Code?

Run `npx skills add netdata/netdata --skill triage-sonarqube -a claude-code`. Or copy the skill folder (.agents/skills/triage-sonarqube in netdata/netdata) into .claude/skills/triage-sonarqube in your project. Claude Code loads it when a task matches its description.

How do I install Triage Sonarqube in Codex?

Run `npx skills add netdata/netdata --skill triage-sonarqube -a codex`. Or copy the skill folder (.agents/skills/triage-sonarqube in netdata/netdata) into .agents/skills/triage-sonarqube in your project. Codex loads it when a task matches its description.

Can I use Triage Sonarqube in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill triage-sonarqube -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-sonarqube, .gemini/skills/triage-sonarqube, .github/skills/triage-sonarqube and .opencode/skills/triage-sonarqube in your project.

What does Triage Sonarqube need to run?

Going by SKILL.md and its folder, Triage Sonarqube needs a shell for the scripts in its folder, the command-line tools its instructions call (bash and jq) and credentials named SONAR_TOKEN, ISSUE_KEY and HOTSPOT_KEY. Our summary lists: Python 3; A Bash shell; Docker; A credential in SONAR_TOKEN; A credential in ISSUE_KEY.

Does Triage Sonarqube access the network?

SKILL.md names 1 domain. In commands or code: sonarcloud.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Triage Sonarqube safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Triage Sonarqube use?

Triage Sonarqube is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triage Sonarqube use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Triage Sonarqube?

Skills that share tags, products or a category with Triage Sonarqube: Sonarqube Analysis (hbmartin/graphviz2drawio, 275 stars), Code Solving (HoangTheQuyen/think-better, 122 stars), AI Development Guide (shinpr/claude-code-workflows, 693 stars) and Ccg Workflow (fengshao1227/ccg-workflow, 5.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triage Sonarqube?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,853 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 9, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.