managing-sonarqube
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell scripts to perform administrative tasks and data retrieval. These scripts rely on standard system utilities such as
curlandjqto interact with the SonarQube API. - [DATA_EXFILTRATION]: Network operations are conducted via
curlto the endpoint specified by the${SONAR_URL}environment variable. While this involves sending authentication tokens (${SONAR_TOKEN}), it is the standard and intended method for interacting with a SonarQube instance and does not represent unauthorized data exfiltration. - [SAFE]: The skill demonstrates defensive coding practices by including "Anti-Hallucination Rules" and "Safety Rules." It correctly advises users to store sensitive tokens in environment variables or CI secrets rather than hardcoding them. No patterns of obfuscation, persistence, or privilege escalation were detected.
Audit Metadata