Quality gate
This skill should be used when the user asks to "run a quality gate", "check code quality", "run lint checks", "run pre-push security scan", "check for dead code", or mentions "quality gate", "quality check", "lint check", "run checks", "code quality", "pre-push scan", "security scan". Provides automated JavaScript/TypeScript code quality enforcement including type checking, linting, formatting, dead code detection, type coverage, circular dependency detection, tests, and security scanning before git push.From its SKILL.md
npx -y skills add iwritec0de/app-dev --skill quality-gateAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- reads credentialsReads from 1 credential source: `SONARQUBE_TOKEN`.
- 3 stars3 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its file declares
Copied from the file, not written here
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
2.9 KB, 609 tokens by cl100k_base, as published. Nobody here has run it
Quality Gate
Automated quality enforcement with two hooks:
Stop Hook — Code Quality
Fires on every session stop. Runs JavaScript/TypeScript checks on changed files:
| Check | Tool | Severity |
|---|---|---|
| Types | tsc --noEmit | BLOCK |
| Lint | eslint | BLOCK on errors, WARN on warnings |
| Format | prettier --check | WARN |
| Tests | jest | BLOCK |
| Dead code | knip (unused exports, deps, files) | WARN |
| Type coverage | type-coverage (>80% threshold) | WARN |
| Circular deps | madge --circular | WARN |
| TODO/FIXME | grep scanner | WARN |
Behavior:
- Missing required tools (tsc, eslint, prettier, jest) = FAIL with install command
- Missing optional tools (knip, type-coverage, madge) = WARN with install suggestion
- Retry limiter: allows stop after 3 consecutive failures
PreToolUse Hook — Security Scan
Intercepts git push commands. Runs 4 scanners in sequence:
-
semgrep — SAST scan on changed files with
--config=auto- Critical/High findings = BLOCK push
- Medium findings = WARN
- Claude should auto-fix findings before retrying
-
gitleaks — scans commits being pushed for leaked secrets
- Any secret found = BLOCK push
-
trivy — filesystem vulnerability, secret, and misconfig scan
- Critical vulns = BLOCK push
- High vulns = WARN
-
SonarQube (optional) — checks quality gate status if configured
- Requires
SONARQUBE_URLandSONARQUBE_TOKENenv vars, plussonar-project.properties - Skipped silently if
SONARQUBE_TOKENis not set - Failed quality gate = BLOCK push
- Requires
Configuration
| Env Var | Default | Purpose |
|---|---|---|
CLAUDE_QUALITY_GATE | 1 | Enable/disable quality gate |
CLAUDE_QUALITY_GATE_MAX_RETRIES | 3 | Max retry attempts before allowing stop |
SONARQUBE_URL | https://sonarqube.internal | SonarQube server URL |
SONARQUBE_TOKEN | (none) | SonarQube auth token |
CLAUDE_NOTIFY_DISCORD | 0 | Send Discord notifications |
DISCORD_WEBHOOK_URL | (none) | Discord webhook for notifications |
Commands
/quality run— Run checks manually/quality status— View gate status and recent results/quality config— See active checks and tool availability
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.