sonarqube-tactics
Warn
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the use of network reconnaissance and exploitation tools such as nmap, hydra, and nuclei to target SonarQube instances.
- [DATA_EXFILTRATION]: The instructions provide specific methods to exfiltrate highly sensitive information, including entire project source code repositories, database connection credentials, and authentication tokens.
- [COMMAND_EXECUTION]: Batch download shell scripts in the documentation use variables derived from remote API responses to construct file system paths. The lack of validation for these variables ($file) could lead to path traversal or arbitrary file writes if the target SonarQube instance is malicious.
- [DATA_EXFILTRATION]: The skill describes how to abuse the Webhook functionality to establish persistent data exfiltration channels to external attacker-controlled infrastructure.
Audit Metadata