sonarqube-ai-slop-gate
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a comprehensive technical reference for SonarQube Server configuration. It provides verified instructions for setting up quality gates, profiles, and server persistence based on product requirements.
- [COMMAND_EXECUTION]: Includes administrative bash scripts designed to interact with the SonarQube Web API for tasks such as flagging AI projects and activating quality rules. These scripts correctly utilize environment variables for sensitive credentials and do not perform any unauthorized data transmission.
- [COMMAND_EXECUTION]: Documents the host-level kernel modifications (
sysctl) required for the application's embedded Elasticsearch component to function. These system-level commands are legitimate infrastructure requirements for the software being deployed. - [EXTERNAL_DOWNLOADS]: References official documentation and assets from
sonarsource.com, which is a well-known and trusted vendor for the technology described.
Audit Metadata