sonarqube

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
skills/sonarqube/SKILL.md

SUSPICIOUS: The skill’s core behavior matches its stated SonarQube purpose and uses official SonarSource infrastructure, so it does not look malicious. However, autonomous code changes, command execution, and especially the localhost admin/admin bootstrap with token persistence to .env make its trust and secret-handling footprint higher than a simple reporting skill.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 7, 2026, 08:46 AM
Package URL
pkg:socket/skills-sh/php-workx%2Fskill-sonarqube%2Fsonarqube%2F@a81af00a129dc906f2406b2e91c57d583555d5b2
Security Audit — socket — sonarqube