{"id":16428,"plugin_id":"plugins_6a3e94fec2448191acee654777a3fd5b","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:13:24.124Z","digest":"1b5fbcedca33dcd83ccff1d0a7cab0a4105ec0f9d1c4936bb3c7044612bc9977","against":null,"payload":{"description":"Analyze a file for quality and security issues using SonarQube","included_files":[],"name":"sonar-analyze","skill_md_contents":"---\nname: sonar-analyze\ndescription: Analyze a file for quality and security issues using SonarQube\nargument-hint: \"[file-path]\"\nallowed-tools: Read, Glob, Bash(git branch:*), Bash(docker ps:*), Bash(podman ps:*), Bash(nerdctl ps:*), Bash(sonar:*)\n---\n\n# SonarQube — Code Analysis\n\nAnalyze code for quality and security issues using the SonarQube MCP Server.\n\n## Usage\n\n```\nsonar-analyze                        # analyze the file currently in context\nsonar-analyze src/auth/login.py      # analyze a specific file\n```\n\n## Prerequisites\n\nThis skill requires the SonarQube MCP Server to be configured and at least one of the tools `mcp__sonarqube__run_advanced_code_analysis` or `mcp__sonarqube__analyze_file_list` to be available in your session.\n\n**Before proceeding**, verify at least one of these tools is accessible. If none are, try the CLI fallback in Step 3 before giving up — don't invent other CLI commands (e.g. `sonar mcp call` does not exist).\n\n**If the CLI fallback also fails or doesn't apply, narrow down the cause** — check whether the `sonarqube` MCP server is enabled in this agent's configuration.\n\n- **Not enabled / not registered** → recommend running the sonar-integrate skill.\n- **Enabled but its tools are still unavailable** → configuration is correct but the server failed to start. The most common cause is that the container runtime is not running — the MCP server launches inside Docker/Podman/Nerdctl via `sonar run mcp`, so a correctly configured server still produces no tools if the daemon is stopped. Run `docker ps` yourself (falling back to `podman ps` / `nerdctl ps`) to confirm which cause applies: if it errors, the runtime is down; after the user starts it, confirm the same command succeeds before asking them to restart the agent session.\n\nEither way, show the user:\n\n> Unable to reach the SonarQube MCP Server.\n>\n> **Possible causes:**\n> - MCP server not registered — invoke the sonar-integrate skill to configure the SonarQube MCP Server, then restart the agent session\n> - Container runtime not running — the SonarQube MCP Server runs inside a container (Docker, Podman, or Nerdctl); start your container runtime, then restart the agent session\n> - Credentials not configured — invoke the sonar-integrate skill\n> - Project key missing or invalid — pass an explicit key if needed, verify `sonar-project.properties`, or re-run the sonar-integrate skill for this project\n\nThen ask the user (yes/no) whether to run the sonar-integrate skill now. Briefly explain what it does: it checks the SonarQube setup on their machine — installing or updating `sonarqube-cli` and verifying authentication — and re-configures the integration for this agent, including the SonarQube MCP server and secrets-scanning hooks. If they confirm, invoke the sonar-integrate skill yourself and follow it end-to-end in this session, then ask the user to ensure a container runtime (Docker, Podman, or Nerdctl) is running and to restart the agent session so the new MCP tools become available; if they decline, stop.\n\n## Instructions\n\n### Step 1: Resolve what to analyze\n\nBoth analysis tools work on **one file at a time**. Resolve a single file path:\n\n- If the user provided a file path, use it.\n- If no path was provided, look at the current conversation context for a recently mentioned or edited file.\n- If nothing is clear, ask: *\"Which file would you like me to analyze?\"*\n\nDo not accept a directory as input. If the user provides one, ask them to specify a single file.\n\n### Step 2: Read the file and determine its scope\n\n1. Read the file's full content — only needed as a fallback for `run_advanced_code_analysis`'s `fileContent` parameter (see Step 3).\n2. Determine the file scope: `\"TEST\"` or `\"MAIN\"`. Use the file path to deduce the scope. For example, if the file path contains `test`, `spec`, or `__tests__`, it's likely `\"TEST\"` scope.\n\n### Step 3: Call the appropriate analysis tool\n\nAfter running the sonar-integrate skill, the SonarQube MCP Server often has a **default project** for this workspace, so **`projectKey` is sometimes unnecessary** — pass it only when the tool schema requires it or the user targets another project.\n\nTwo tools may be available depending on whether the connected organization is eligible for Vortex analysis:\n\n**Try `mcp__sonarqube__run_advanced_code_analysis` first** (available when the organization is eligible for Vortex analysis).\n\nBefore calling it, detect the current branch name using `git branch --show-current`. If git is unavailable, use `main` as a fallback.\n\nThen call with:\n\n- `projectKey` — **omit unless the tool requires it** (initial MCP configuration usually supplies the default project); if required, use the value from the user's arguments if provided, otherwise `sonar.projectKey` in `sonar-project.properties` at the repo root\n- `branchName` — detected branch name\n- `filePath` — project-relative file path (e.g. `src/auth/login.py`)\n- `fileContent` — full file content; **only pass if the tool requires it** (when the MCP server has a mount, it reads the file directly and this parameter will not be required)\n- `fileScope` — `[\"TEST\"]` or `[\"MAIN\"]`\n\n**If that tool is unavailable, fall back to `mcp__sonarqube__analyze_file_list`** (requires a running SonarQube for IDE instance bridged to this session):\n\n- `file_absolute_paths` — array containing the absolute path to the file (e.g. `[\"/home/user/project/src/auth/login.py\"]`); resolve it from the file path found in Step 1\n\n**If neither MCP tool is available, fall back to the CLI's Vortex analysis:**\n\n```bash\nsonar analyze agentic --file <file-path> [--file <other-file-path> ...] --format json [--branch <branch-name>] [-p <project-key>]\n```\n\nSame backend as `run_advanced_code_analysis` (repeatable `--file` covers multi-file too), and the practical fallback for `analyze_file_list` as well — it has no direct CLI equivalent, but this achieves the same goal.\n\nRequires a Vortex analysis-eligible organization. If the org isn't eligible, or `sonar` isn't installed/authenticated, show the standard message from Prerequisites — don't guess further commands.\n\n### Step 4: Format the results\n\n**If issues are found**, present them as a table sorted by line number:\n\n```markdown\n## SonarQube Analysis — `src/auth/login.py`\n\nFound **3 issue(s)**:\n\n| Line | Severity  | Rule         | Message                                               |\n| ---- | --------- | ------------ | ----------------------------------------------------- |\n| 12   | 🔴 Blocker | python:S2077 | Make sure that executing this SQL query is safe here. |\n| 34   | 🟠 Major   | python:S1481 | Remove the unused local variable \"token\".             |\n| 67   | 🟡 Minor   | python:S1135 | Complete the task associated to this \"TODO\" comment.  |\n```\n\nSeverity icons (the label depends on the server version):\n- 🔴 Blocker\n- 🟠 Critical / High\n- 🟡 Major / Medium\n- 🔵 Minor / Low\n- ⚪ Info\n\n**If no issues are found**:\n\n```markdown\n## SonarQube Analysis — `src/auth/login.py`\n\n✅ No issues found.\n```\n\n### Step 5: Next steps\n\nAfter the results, always add:\n\n- If issues were found: *\"Invoke the sonar-fix-issue skill with `<rule> <file>:<line>` to fix a specific issue, or ask me to fix them all.\"*\n- If the user wants to analyze another file: remind them to invoke the sonar-analyze skill with the file path.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}