Official agent skill

Sonar Fix Issue

by SonarSource in SonarSource/sonarqube-agent-plugins

Fix a specific SonarQube issue in code by rule key and location

OfficialCustom licenceAuto-check passed

Install Sonar Fix Issue

skills CLI
$ npx skills add SonarSource/sonarqube-agent-plugins --skill sonar-fix-issue -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SonarSource/sonarqube-agent-plugins sonar-fix-issue --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SonarSource/sonarqube-agent-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sonar-fix-issue .claude/skills/sonar-fix-issue && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sonar-fix-issue
GitHub stars
111
Token cost
~551 tokens
SKILL.md length
278 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
Custom licence

At a glance

Fix a specific SonarQube issue in code by rule key and location

  • Works in 6 steps: Identify the issue → Look up the rule (if a key was given) → Read the file → …
  • SKILL.md covers Usage and Instructions
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sonar Fix Issue is an agent skill from SonarSource/sonarqube-agent-plugins, published by the product's own GitHub organization. Fix a specific SonarQube issue in code by rule key and location

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: SonarQube Plugin for AI Agents.

Example prompts

  • “/sonar-fix-issue”

Requirements

  • Pre-approved tools (allowed-tools): Read, Edit, Bash(sonar:*)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify the issue
  2. Look up the rule (if a key was given)
  3. Read the file
  4. Apply the fix
  5. Explain the change
  6. Suggest next steps

What it can do on your machine

Read from SKILL.md and the folder at commit 6142e57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Bash(sonar:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sonar Fix Issue loads about 551 tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 278 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~551

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 278 words (~551 tokens).

“Fix a code quality or security issue identified by SonarQube.”

— opening of SKILL.md by SonarSource, Custom licence
name
sonar-fix-issue
allowed-tools
Read, Edit, Bash(sonar:*)
argument-hint
[rule-key] [file-path:line]

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/sonar-fix-issue of SonarSource/sonarqube-agent-plugins.

Open the folder on GitHubat commit 6142e57

Compare with similar skills

Sonar Fix Issue next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sonar Fix Issue compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sonar Fix Issue this skillSonarSource/sonarqube-agent-plugins111—~551Automated safety check: PassCustom licence
Codex Rules Referencecode-yeongyu/oh-my-openagent70k—~269Automated safety check: PassCustom licence
Rules Distillationaffaan-m/ECC275k2 repos~2.3kAutomated safety check: PassMIT
Triage Sonarqubenetdata/netdata81k—~2.8kAutomated safety check: NotesGPL-3.0
New Rule for sonar-javaSonarSource/sonar-java1.2k—~833Automated safety check: PassCustom licence
Hookify Rulesaffaan-m/ECC275k—~605Automated safety check: NotesMIT

Similar skills

  • Codex Rules Reference

    code-yeongyu/oh-my-openagent

    Explains how the Codex Rules plugin injects project instructions and file-specific rules into a session, which rule files it reads and which settings control it.

    70k GitHub stars~269 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    275k GitHub starsUsed in 2 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Testing & QAAuto-check: notes
  • New Rule for sonar-java

    SonarSource/sonar-java

    Official

    Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

    1.2k GitHub stars~833 tokensUpdated today
    DevelopmentAuto-check passed
  • Hookify Rules

    affaan-m/ECC

    当用户要求创建hookify规则、编写hook规则、配置hookify、添加hookify规则或需要关于hookify规则语法和模式的指导时,应使用此技能。

    275k GitHub stars~605 tokensUpdated 3 days ago
    Agent WorkflowsAuto-check: notes
  • Rules Distill

    affaan-m/ECC

    スキルをスキャンしてドメイン横断的な原則を抽出し、ルールに蒸留する——既存のルールファイルへの追記、修正、または新規作成

    275k GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed

More from SonarSource/sonarqube-agent-plugins

All 8 skills in this repo
  • Sonar Analyze

    SonarSource/sonarqube-agent-plugins

    Official

    Analyze a file for quality and security issues using SonarQube

    111 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Sonar Coverage

    SonarSource/sonarqube-agent-plugins

    Official

    Find files with low test coverage and inspect uncovered lines in a SonarQube project (project key optional when MCP integration already defines the default project)

    111 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Sonar Dependency Risks

    SonarSource/sonarqube-agent-plugins

    Official

    Search for software composition analysis (SCA) dependency risks in a SonarQube project (project key optional when MCP integration already defines the default project)

    111 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Sonar Duplication

    SonarSource/sonarqube-agent-plugins

    Official

    Find files with code duplications in a SonarQube project and inspect duplication blocks for a file (project key optional when MCP integration already defines the default project)

    111 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Sonar List Issues

    SonarSource/sonarqube-agent-plugins

    Official

    Search and filter SonarQube issues for a project, branch, or pull request via sonarqube-cli (-p is always required on the CLI; resolve the key from user arguments or sonar-project.properties)

    111 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sonar List Projects

    SonarSource/sonarqube-agent-plugins

    Official

    List SonarQube projects accessible to the current user. An agent skill from SonarSource/sonarqube-agent-plugins.

    111 GitHub stars~741 tokensUpdated yesterday
    Auto-check passed

Questions about Sonar Fix Issue

What does Sonar Fix Issue do?

Fix a specific SonarQube issue in code by rule key and location. Sonar Fix Issue is an agent skill from SonarSource/sonarqube-agent-plugins, published by the product's own GitHub organization.

How do I install Sonar Fix Issue in Claude Code?

Run `npx skills add SonarSource/sonarqube-agent-plugins --skill sonar-fix-issue -a claude-code`. Or copy the skill folder (skills/sonar-fix-issue in SonarSource/sonarqube-agent-plugins) into .claude/skills/sonar-fix-issue in your project. Claude Code loads it when a task matches its description.

How do I install Sonar Fix Issue in Codex?

Run `npx skills add SonarSource/sonarqube-agent-plugins --skill sonar-fix-issue -a codex`. Or copy the skill folder (skills/sonar-fix-issue in SonarSource/sonarqube-agent-plugins) into .agents/skills/sonar-fix-issue in your project. Codex loads it when a task matches its description.

Can I use Sonar Fix Issue in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SonarSource/sonarqube-agent-plugins --skill sonar-fix-issue -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sonar-fix-issue, .gemini/skills/sonar-fix-issue, .github/skills/sonar-fix-issue and .opencode/skills/sonar-fix-issue in your project.

What does Sonar Fix Issue need to run?

SKILL.md names no scripts, command-line tools or credentials: Sonar Fix Issue is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Edit, Bash(sonar:*).

Does Sonar Fix Issue access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sonar Fix Issue safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sonar Fix Issue use?

Sonar Fix Issue has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Sonar Fix Issue use?

About 551 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sonar Fix Issue?

Skills that share tags, products or a category with Sonar Fix Issue: Codex Rules Reference (code-yeongyu/oh-my-openagent, 70k stars), Rules Distillation (affaan-m/ECC, 275k stars), Triage Sonarqube (netdata/netdata, 81k stars) and New Rule for sonar-java (SonarSource/sonar-java, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sonar Fix Issue?

SonarSource (a GitHub organization, an official publisher) maintains it in SonarSource/sonarqube-agent-plugins, which has 111 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 7, 2026.

Source: SonarSource/sonarqube-agent-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.