agentsclimarketplace

Sonarqube check

Skill byerlikaya/claude-starter-kit/claude-starter/skills/sonarqube-check

Enterprise engineering workflow for Claude Code — not just prompts. AI agents that plan, build, audit, and ship with security gates, privacy checks, and approval-controlled commits. Safely adopt it into new or existing repositories.

Install
npx -y skills add byerlikaya/claude-starter-kit --skill sonarqube-check

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 20 stars20 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

SonarQube quality gate (language-agnostic, local-first): 0 Bugs/Vulns/Hotspots/Code Smells, 0 build warnings. If no analyzer exists, install the language's local server-less Sonar analyzer and run it — never a remote server. Trigger phrases: "sonarqube", "quality gate", "code smell", "sonar scan"

SKILL.md

3.2 KB, 775 tokens by cl100k_base, as published. Nobody here has run it

SonarQube Quality Gate (language-agnostic, local-first)

Zero-tolerance gate: a job does not close until the metrics below are clean. The analysis runs locally — it never depends on a shared or remote SonarQube server. If the project has no analyzer wired, this gate installs the language's local, server-less analyzer and runs it itself (no host URL, no token, nothing to reach).

Gate (all mandatory)

  • 0 Bugs · 0 Vulnerabilities · 0 Security Hotspots · 0 Code Smells
  • Build 0 warnings / 0 errors
  • Coverage above the threshold the project defines (especially on new code)

The rule: bootstrap a local analyzer when absent

Detect the stack, then — if no analyzer is configured — install the local one and analyze in place:

StackLocal, server-less analyzer (install if missing)Runs on
.NET / C#SonarAnalyzer.CSharp NuGet (SonarSource Roslyn rules, build-time) + <TreatWarningsAsErrors>every dotnet build
JS / TSeslint-plugin-sonarjs (SonarSource's JS/TS rules inside ESLint)eslint .
Pythonbandit (security) + pylint/ruff (Sonar-equivalent local rules)run in CI/pre-commit
Java / KotlinSpotBugs + PMD (local rulesets), or the SonarLint CLIbuild task
Go / PHP / otherthe language's Sonar-rule linter, run locallyits own runner

For .NET — the case here — wire the analyzer once so every build enforces the rules, then the build itself is the gate:

<!-- Directory.Build.props (repo root) — applies to every project -->
<Project>
  <ItemGroup>
    <PackageReference Include="SonarAnalyzer.CSharp" Version="*" PrivateAssets="all" />
  </ItemGroup>
  <PropertyGroup>
    <TreatWarningsAsErrors>true</TreatWarningsAsErrors>
    <AnalysisLevel>latest-all</AnalysisLevel>
  </PropertyGroup>
</Project>
dotnet build --no-incremental   # any Sonar rule (Sxxxx) now fails the build → the 0/0/0/0 gate

This is exactly "install the analyzer and let it analyze itself" — no server, no token, offline-capable.

Optional: a full SonarQube dashboard

Only when the project already runs its own SonarQube (self-hosted, or a local Docker Community instance it set up) do you also push results for the dashboard — via dotnet sonarscanner begin/end or sonar-scanner. Never bind to an external/shared server the project did not set up. The local analyzer above is the gate; the dashboard is extra.

Principles

  • Clean as You Code: the gate is zero on new/changed code; legacy debt is handled separately, but no new debt is added.
  • Security Hotspots are not ignored: each one is reviewed and either marked "safe" with a rationale or fixed.
  • Finding → the relevant expert fixes it; no deferral, no "we'll look at it later".

DoD

  • Local analyzer installed (if it was missing) and PASSED: 0/0/0/0, build 0 warnings / 0 errors; green before PR/merge.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.