managing-sonarqube

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell scripts to perform administrative tasks and data retrieval. These scripts rely on standard system utilities such as curl and jq to interact with the SonarQube API.
  • [DATA_EXFILTRATION]: Network operations are conducted via curl to the endpoint specified by the ${SONAR_URL} environment variable. While this involves sending authentication tokens (${SONAR_TOKEN}), it is the standard and intended method for interacting with a SonarQube instance and does not represent unauthorized data exfiltration.
  • [SAFE]: The skill demonstrates defensive coding practices by including "Anti-Hallucination Rules" and "Safety Rules." It correctly advises users to store sensitive tokens in environment variables or CI secrets rather than hardcoding them. No patterns of obfuscation, persistence, or privilege escalation were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 03:16 AM
Security Audit — agent-trust-hub — managing-sonarqube