sonarqube-bootstrap

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional, focusing on providing guidance for SonarQube service setup and documentation management. It does not contain any malicious patterns such as credential exfiltration, remote code execution, or prompt injection.
  • [COMMAND_EXECUTION]: The skill mentions running git diff --check as part of its quality expectations. This is a standard, non-destructive command used in development workflows to check for whitespace errors and other minor formatting issues.
  • [DATA_EXPOSURE]: There is no evidence of sensitive data exposure. The skill explicitly mentions 'Credential and token handling rules' as an input and includes STOP conditions for unclear secret handling, indicating a focus on safe credential management practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 07:03 AM
Security Audit — agent-trust-hub — sonarqube-bootstrap