sonarqube-bootstrap
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily instructional, focusing on providing guidance for SonarQube service setup and documentation management. It does not contain any malicious patterns such as credential exfiltration, remote code execution, or prompt injection.
- [COMMAND_EXECUTION]: The skill mentions running
git diff --checkas part of its quality expectations. This is a standard, non-destructive command used in development workflows to check for whitespace errors and other minor formatting issues. - [DATA_EXPOSURE]: There is no evidence of sensitive data exposure. The skill explicitly mentions 'Credential and token handling rules' as an input and includes STOP conditions for unclear secret handling, indicating a focus on safe credential management practices.
Audit Metadata