sonarqube

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
skills/sonarqube/SKILL.md

SUSPICIOUS: The skill’s core behavior matches its stated SonarQube purpose and uses official SonarSource infrastructure, so it does not look malicious. However, autonomous code changes, command execution, and especially the localhost admin/admin bootstrap with token persistence to .env make its trust and secret-handling footprint higher than a simple reporting skill.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 7, 2026, 08:46 AM
Package URL
pkg:socket/skills-sh/php-workx%2Fskill-sonarqube%2Fsonarqube%2F@a81af00a129dc906f2406b2e91c57d583555d5b2