sonarqube-triage

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured process for handling external data from SonarQube APIs. While it ingests data from an external system, it does so within the intended context of a quality management toolset.
  • Ingestion points: External data is ingested from SonarQube project scans through tools like search_sonar_issues_in_projects and get_issue.
  • Boundary markers: The skill uses structured templates for delegation and TODO creation, providing consistent formatting for external data interpolation.
  • Capability inventory: Capabilities are scoped to reading/writing SonarQube issue statuses, project metrics, and creating local project TODOs.
  • Sanitization: The skill follows predefined formats for reporting findings, which helps maintain structure when processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:16 AM
Security Audit — agent-trust-hub — sonarqube-triage