Official agent skill

New Rule for sonar-java

by SonarSource in SonarSource/sonar-java

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

OfficialCustom licenceAuto-check passedDevelopment

Install New Rule for sonar-java

skills CLI
$ npx skills add SonarSource/sonar-java --skill new-rule -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SonarSource/sonar-java new-rule --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SonarSource/sonar-java.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/new-rule .claude/skills/new-rule && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
new-rule
GitHub stars
1.2k
Token cost
~833 tokens
SKILL.md length
282 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Custom licence

At a glance

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

  • Works in 4 steps: Version Control → Build Configuration → Architecture → …
  • Implementing a new Java static-analysis rule in sonar-java
  • SKILL.md covers What to Do, What NOT to Do and File Structure Reference
  • Calls java

What it does

The skill lists sonar-java-specific do's and don'ts for writing a new rule. Metadata comes from the rule-api tool run against an up-to-date RSPEC repository checkout and the rule branch, which generates HTML and JSON files under the sonar-java-plugin resources and updates the Sonar way profile. The rule class lives in java-checks with a matching test class, and ruling test expectation files under its/ruling are updated by merging an automatically generated PR when CI checks fail.

MethodMatchers are the tool for matching method calls by type, name and signature. Tests must not add external library dependencies; mock-ups or non-compiling test samples take their place, as the Spring examples show. The don'ts are firm: no log files or temporary files in version control, no pom.xml edits unless the rule needs them, and no architectural changes, since new rules should follow similar existing ones.

When your agent uses it

  • Implementing a new Java static-analysis rule in sonar-java
  • Generating rule metadata with rule-api from an RSPEC branch
  • Writing test samples for a rule that involves external libraries
  • Matching method calls in a check with MethodMatchers

Example prompts

  • “Implement the new rule from the RSPEC branch in sonar-java and generate its metadata.”
  • “Write non-compiling test samples for a Spring-related check.”
  • “Which files should I leave alone when adding a rule to sonar-java?”

Requirements

  • A local RSPEC repository checkout
  • The rule-api jar
  • Java and Maven

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Version Control
  2. Build Configuration
  3. Architecture
  4. Test Dependencies

What it can do on your machine

Read from SKILL.md and the folder at commit d34c9c3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • java

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

New Rule for sonar-java loads about 833 tokens when it runs. Until then it costs about 15 tokens; SKILL.md has 282 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~833

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 282 words (~833 tokens).

“This skill provides sonar-java-specific guidelines for implementing new rules.”

— opening of SKILL.md by SonarSource, Custom licence
name
new-rule

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/new-rule of SonarSource/sonar-java.

Open the folder on GitHubat commit d34c9c3

Compare with similar skills

New Rule for sonar-java next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

New Rule for sonar-java compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
New Rule for sonar-java this skillSonarSource/sonar-java1.2k—~833Automated safety check: PassCustom licence
111 Java Maven Dependenciesjabrena/plinth445—~1.5kAutomated safety check: PassApache-2.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT
Code Qualitypiomin/claude-ai-spring-boot1.3k—~2.2kAutomated safety check: PassApache-2.0
Skylosduriantaco/skylos843—~581Automated safety check: PassApache-2.0

Similar skills

  • A skill your agent uses when you need to add or evaluate Maven dependencies that improve code quality or domain modeling — including nullness annotations (JSpecify), static analysis (Error Prone +…

    445 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Code Quality

    piomin/claude-ai-spring-boot

    Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance.

    1.3k GitHub stars~2.2k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Skylos

    duriantaco/skylos

    Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

    843 GitHub stars~581 tokensUpdated yesterday
    SecurityAuto-check passed
  • Android Code Quality Checker

    wordpress-mobile/WordPress-Android

    Runs detekt, checkstyle, and Android lint together, reads their reports, and proposes approved fixes grouped by file.

    3.2k GitHub stars~587 tokensUpdated yesterday
    DevelopmentAuto-check passed

Works with

Questions about New Rule for sonar-java

What does New Rule for sonar-java do?

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. The skill lists sonar-java-specific do's and don'ts for writing a new rule. Metadata comes from the rule-api tool run against an up-to-date RSPEC repository checkout and the rule branch, which generates HTML and JSON files under the sonar-java-plugin resources and updates the Sonar way profile.

When should I use New Rule for sonar-java?

New Rule for sonar-java fits situations like: implementing a new Java static-analysis rule in sonar-java; generating rule metadata with rule-api from an RSPEC branch; writing test samples for a rule that involves external libraries; matching method calls in a check with MethodMatchers.

How do I install New Rule for sonar-java in Claude Code?

Run `npx skills add SonarSource/sonar-java --skill new-rule -a claude-code`. Or copy the skill folder (.claude/skills/new-rule in SonarSource/sonar-java) into .claude/skills/new-rule in your project. Claude Code loads it when a task matches its description.

How do I install New Rule for sonar-java in Codex?

Run `npx skills add SonarSource/sonar-java --skill new-rule -a codex`. Or copy the skill folder (.claude/skills/new-rule in SonarSource/sonar-java) into .agents/skills/new-rule in your project. Codex loads it when a task matches its description.

Can I use New Rule for sonar-java in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SonarSource/sonar-java --skill new-rule -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/new-rule, .gemini/skills/new-rule, .github/skills/new-rule and .opencode/skills/new-rule in your project.

What does New Rule for sonar-java need to run?

Going by SKILL.md and its folder, New Rule for sonar-java needs the command-line tools its instructions call (java). Our summary lists: A local RSPEC repository checkout; The rule-api jar; Java and Maven.

Does New Rule for sonar-java access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is New Rule for sonar-java safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does New Rule for sonar-java use?

New Rule for sonar-java has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does New Rule for sonar-java use?

About 833 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to New Rule for sonar-java?

Skills that share tags, products or a category with New Rule for sonar-java: 111 Java Maven Dependencies (jabrena/plinth, 445 stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Cross-Language Coding Standards (zereight/gitlab-mcp, 2k stars) and Code Quality (piomin/claude-ai-spring-boot, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains New Rule for sonar-java?

SonarSource (a GitHub organization, an official publisher) maintains it in SonarSource/sonar-java, which has 1,220 GitHub stars. The repository was last updated on October 7, 2026.

Source: SonarSource/sonar-java on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.