sonarqube-mcp
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code snippets and issue text reports via standard SonarQube integration boundaries (
SKILL.mdStep 4). It enforces safe practices by keeping actions scoped exclusively to analytical read-only inputs or metadata checks, completely separating untrusted execution flows from system operations. - [COMMAND_EXECUTION]: Code examples showcase environment configuration exports for tokens and organizational parameters (
SKILL.md). These are standard operational instructions for developers, presenting no risky dynamic construction or shell exploitation paths.
Audit Metadata