Sonarqube Analysis
hbmartin/graphviz2drawio
Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials.
Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.
$ npx skills add netdata/netdata --skill triage-sonarqube -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install netdata/netdata triage-sonarqube --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/triage-sonarqube .claude/skills/triage-sonarqube && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "triage-sonarqube" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/triage-sonarqube into .claude/skills/triage-sonarqube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-sonarqube", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/netdata/netdata/tree/master/.agents/skills/triage-sonarqubeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add netdata/netdata --skill triage-sonarqube -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install netdata/netdata triage-sonarqube --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/triage-sonarqube .agents/skills/triage-sonarqube && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "triage-sonarqube" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/triage-sonarqube into .agents/skills/triage-sonarqube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-sonarqube", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add netdata/netdata --skill triage-sonarqube -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install netdata/netdata triage-sonarqube --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/triage-sonarqube .cursor/skills/triage-sonarqube && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "triage-sonarqube" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/triage-sonarqube into .cursor/skills/triage-sonarqube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-sonarqube", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/netdata/netdata.git --path .agents/skills/triage-sonarqube--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add netdata/netdata --skill triage-sonarqube -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install netdata/netdata triage-sonarqube --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/triage-sonarqube .gemini/skills/triage-sonarqube && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "triage-sonarqube" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/triage-sonarqube into .gemini/skills/triage-sonarqube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-sonarqube", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install netdata/netdata triage-sonarqubeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add netdata/netdata --skill triage-sonarqube -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/triage-sonarqube .github/skills/triage-sonarqube && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "triage-sonarqube" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/triage-sonarqube into .github/skills/triage-sonarqube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-sonarqube", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add netdata/netdata --skill triage-sonarqube -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install netdata/netdata triage-sonarqube --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/triage-sonarqube .opencode/skills/triage-sonarqube && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "triage-sonarqube" agent skill from https://github.com/netdata/netdata/tree/master/.agents/skills/triage-sonarqube into .opencode/skills/triage-sonarqube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-sonarqube", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
triage-sonarqubeInspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.
Triage Sonarqube is an agent skill from netdata/netdata. Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers. Use for SonarQube/SonarCloud findings, code smells, vulnerabilities, and quality-gate evidence. Supplied evidence needs no live query; per-finding writes and project-wide policy changes have distinct scopes.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `how-tos/INDEX.md`, `how-tos/triage-pr-duplication-gate.md` and `scripts/_lib.sh`).
It sits in Testing & QA, covering Refactoring and Quality gates. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a7f3cf9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
bashjqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
sonarcloud.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SONAR_TOKENISSUE_KEYHOTSPOT_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Triage Sonarqube loads about 2.8k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 1,187 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Scripts use the project configured in `.env` and keep audit artifacts under `<repo>/.local/`. Read only the sections### .env entries| Missing `.env` for a public PR query | Try `https://sonarcloud.io/api/issues/search` with `componentKeys`, `pullRequAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from netdata/netdata at commit a7f3cf9, republished under its GPL-3.0 licence (© netdata). 1,187 words, ~2,827 tokens.
.claude/skills/triage-sonarqube/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Use the requested operation to select the workflow. Loading this skill does not authorize remote transitions, comments, risk acceptance or changes to analysis policy.
| Task | Route |
|---|---|
| Review supplied findings or helper changes | Inspect the provided evidence and affected source; use the decision matrix as review criteria without credential setup or live requests |
| Inspect current findings | Search only the requested project/PR/rule scope with configured credentials; preserve current source and analysis provenance |
| Apply authorized triage | Verify each finding and its classification, then use the selected-key commands below |
| Change a whole rule family or project policy | Establish evidence and authorization for that complete scope before applying the family/profile procedure |
Scripts use the project configured in .env and keep audit artifacts under <repo>/.local/. Read only the sections
needed for the task; ordinary finding review does not require profile configuration.
Capture timing and authorization for operational discoveries follow AGENTS.md#knowledge-capture.
Examples of things to capture:
Setup is for live helper execution. Reuse configured credentials through the helper; never ask for tokens in the conversation. Offline evidence review does not need setup.
# SonarCloud
SONAR_TOKEN='<paste your token from https://sonarcloud.io/account/security>'
SONAR_HOST_URL=https://sonarcloud.io
SONAR_PROJECT=<project_key, e.g. netdata_netdata>
SONAR_ORG=<organization_key, e.g. netdata>The token is used as HTTP Basic auth username with empty password:
-u "$SONAR_TOKEN:" (note the trailing colon).
No browser tab is required for token-based auth. Tokens can expire or be revoked; verify access when executing.
| Decision | API transition | When to use |
|---|---|---|
| Confirm | confirm | Sonar is right, we're going to fix it |
| Won't Fix | wontfix | Real but acceptable — won't fix (e.g., legacy code being deleted) |
| False Positive | falsepositive | Sonar is wrong (guard exists, unreachable, tool model error) |
Hotspots have a separate state machine. They go from TO_REVIEW to
REVIEWED with one of three resolutions:
| Resolution | When to use |
|---|---|
SAFE | Hotspot reviewed, code is fine as-is (no risk in context) |
ACKNOWLEDGED | Risk understood, no immediate action — leave for future review |
FIXED | Hotspot reviewed and the code was changed to remove the risk |
The helpers enforce ASCII-only comments before the network round-trip. This preserves a workaround for observed 403 challenges with non-ASCII bodies; it does not establish a universal current Cloudflare rule.
-- instead of em-dash (U+2014)." ' instead of smart quotes.bash .agents/skills/triage-sonarqube/scripts/sonar-search.sh summaryPrints per-rule counts of open issues and hotspots. Use volume to prioritize inspection. A count or shared rule ID is not evidence that every finding is false positive, safe, or covered by the same exclusion.
Issues:
bash .agents/skills/triage-sonarqube/scripts/sonar-search.sh issues --rule cpp:S5827Hotspots:
bash .agents/skills/triage-sonarqube/scripts/sonar-search.sh hotspots --status=TO_REVIEW \
| jq '.hotspots[] | select(.ruleKey=="c:S5443")'Before writing, verify the selected finding against reachable code, its current state and the matrix above. Record
why the classification fits; FIXED requires the relevant code change. A request to inspect or review remains read-only.
Existing authorization to apply the verified decisions persists; do not add another approval round for routine execution.
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh fp <ISSUE_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh wontfix <ISSUE_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh confirm <ISSUE_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh safe <HOTSPOT_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh ack <HOTSPOT_KEY> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh fixed <HOTSPOT_KEY> "<COMMENT>"bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh family-fp <RULE_ID> "<COMMENT>"
bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh family-safe <RULE_ID> "<COMMENT>"Prefer single-key commands for a reviewed subset. Family mode re-enumerates every currently open finding for the rule; it cannot express a selected path or evidence subset. Use it only when the evidence and user authorization cover that entire current set. Otherwise apply the already verified keys individually.
Family mode prints matched keys and prompts unless SONAR_MARK_YES=1 is set. That variable skips the helper prompt;
it does not grant user authorization or extend it to newly discovered findings.
SONAR_DRY_RUN=1 bash .agents/skills/triage-sonarqube/scripts/sonar-mark.sh fp KEY "Comment"In dry-run mode, write API calls (mark issues, change hotspot status, add comments) are printed but not executed. Read API calls (issue search, hotspot search used to enumerate findings in family mode) still run -- otherwise family mode could not show what it would have acted on.
These are separate project-policy operations, not effects of per-finding triage. Perform them only when that scope is authorized:
api/qualityprofiles/deactivate_rule; the SonarCloud UI also exposes Quality Profiles.Effective profile lookup:
GET /api/qualityprofiles/search?project=$SONAR_PROJECT&organization=$SONAR_ORGBefore an authorized project-wide change, inspect the effective profile, ownership, inheritance and other projects
using it. Reuse an appropriate editable profile when the approved scope covers its consumers. If the inherited
profile cannot be edited or its other consumers must remain unaffected, the API supports copying it
(api/qualityprofiles/copy), editing the copy, and assigning this project (api/qualityprofiles/add_project). Verify
the resulting effective profile; do not create a fresh copy automatically on every run.
SonarCloud language keys include:
c, cpp, go, javascript, py, shell, plsql, docker, css,
ipynb, php (and others depending on the project). Note the rule-id
namespaces in api/issues/search results may differ from the language
keys -- e.g. shell rules use the shelldre: prefix, Go rules can use
either go: or godre: depending on which analyzer fired -- so the
language argument to qualityprofile APIs is the SHORT key (shell,
go), not the rule-namespace prefix.
Keep a record of profile decisions in a project-local doc under
.local/audits/sonarqube/.
| Symptom | Likely cause |
|---|---|
| HTTP 401 / 403 with HTML body | Token wrong/expired, or Cloudflare blocking non-ASCII |
Missing .env for a public PR query | Try https://sonarcloud.io/api/issues/search with componentKeys, pullRequest, sinceLeakPeriod=true, and statuses=OPEN,CONFIRMED; anonymous reads have worked for public projects, but availability must be checked; failure is an evidence gap. |
| Token works for issues but not hotspots | Hotspot endpoints have separate auth checks — token must have Browse permission |
| Family-mode appears to stop at 500 | Outdated -- sonar-mark.sh family-mode now paginates transparently via sq_paginate. If you still see truncation, check sq_paginate's array-key recognition list. |
falsepositive transition rejected | Check current state, available transitions and permissions; do not assume a previously supported transition is still available |
| Hotspot transition rejected | Re-check current state, available resolutions and permissions before retry |
argparse.parse_args() as HTTP input while overlooking choices= validation. Check enum-derived flags,
absolute file arguments and operator-selected executables separately. shlex.join() used only in a printed
diagnostic or exception message is display text, not execution. Verify each source/sink before classification;
this pattern does not justify marking a whole rule family false positive.api/issues/search is paged at ps=500 max. The sq_paginate helper
in _lib.sh walks every page until paging.total; use it from any
new script instead of re-implementing the loop.api/measures/component_tree are stored
under measures[].periods[0].value, not measures[].value. This matters for
quality-gate metrics such as new_duplicated_lines,
new_duplicated_lines_density, and new_lines.ruleKey filtering is client-side (search only filters by
status/project), so the family-mode helper does it with jq.SONAR_DRY_RUN=1 is the right knob when iterating on comments
before committing to a bulk operation.© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts) in .agents/skills/triage-sonarqube of netdata/netdata.
Open the folder on GitHubat commit a7f3cf9
Triage Sonarqube next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Triage Sonarqube this skillnetdata/netdata | 81k | — | ~2.8k | Automated safety check: Notes | GPL-3.0 | |
| Sonarqube Analysishbmartin/graphviz2drawio | 275 | — | ~508 | Automated safety check: Notes | GPL-3.0 | |
| Code SolvingHoangTheQuyen/think-better | 122 | — | ~3.7k | Automated safety check: Pass | MIT | |
| AI Development Guideshinpr/claude-code-workflows | 693 | — | ~3.9k | Automated safety check: Pass | MIT | |
| Ccg Workflowfengshao1227/ccg-workflow | 5.9k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Sonarcloud Reviewlucasvieirasilva/nx-plugins | 153 | — | ~2.7k | Automated safety check: Notes | MIT |
hbmartin/graphviz2drawio
Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials.
HoangTheQuyen/think-better
Structured coding workflow for non-trivial code work: debug, build features, refactor, optimize, migrate and review code through 7 steps with evidence-based quality gates.
shinpr/claude-code-workflows
Applies language-agnostic and backend technical decision criteria, anti-pattern detection, debugging, and quality gates.
fengshao1227/ccg-workflow
How to run a non-trivial change end to end with the CCG role tools (ccganalyze / ccgdesign / ccgbuild / ccgdebug / ccgoptimize / ccgreview / ccgtest) and the verify- quality gates.
lucasvieirasilva/nx-plugins
Fetches and triages SonarCloud findings (issues, security hotspots, quality gate) for the current pull request or branch of this repository via the SonarCloud Web API, summarizes them in a markdown…
Cod-e-Codes/marchat
Implements and refactors marchat Go code with project toolchain and quality gates.
netdata/netdata
Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.
netdata/netdata
Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.
netdata/netdata
Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.
netdata/netdata
Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.
netdata/netdata
Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.
netdata/netdata
Create, review or validate Netdata Prometheus chart profiles, exporter dashboard design, collection policy and stock semantic proofs.
Categories
Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers. Triage Sonarqube is an agent skill from netdata/netdata. Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.
Triage Sonarqube fits situations like: sonarQube/SonarCloud findings; vulnerabilities; quality-gate evidence.
Run `npx skills add netdata/netdata --skill triage-sonarqube -a claude-code`. Or copy the skill folder (.agents/skills/triage-sonarqube in netdata/netdata) into .claude/skills/triage-sonarqube in your project. Claude Code loads it when a task matches its description.
Run `npx skills add netdata/netdata --skill triage-sonarqube -a codex`. Or copy the skill folder (.agents/skills/triage-sonarqube in netdata/netdata) into .agents/skills/triage-sonarqube in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill triage-sonarqube -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-sonarqube, .gemini/skills/triage-sonarqube, .github/skills/triage-sonarqube and .opencode/skills/triage-sonarqube in your project.
Going by SKILL.md and its folder, Triage Sonarqube needs a shell for the scripts in its folder, the command-line tools its instructions call (bash and jq) and credentials named SONAR_TOKEN, ISSUE_KEY and HOTSPOT_KEY. Our summary lists: Python 3; A Bash shell; Docker; A credential in SONAR_TOKEN; A credential in ISSUE_KEY.
SKILL.md names 1 domain. In commands or code: sonarcloud.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Triage Sonarqube is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Triage Sonarqube: Sonarqube Analysis (hbmartin/graphviz2drawio, 275 stars), Code Solving (HoangTheQuyen/think-better, 122 stars), AI Development Guide (shinpr/claude-code-workflows, 693 stars) and Ccg Workflow (fengshao1227/ccg-workflow, 5.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,853 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 9, 2026.
Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.