sonarqube
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalyskills/sonarqube/SKILL.md
LOWAnomalyLOW
skills/sonarqube/SKILL.md
SUSPICIOUS: The skill’s core behavior matches its stated SonarQube purpose and uses official SonarSource infrastructure, so it does not look malicious. However, autonomous code changes, command execution, and especially the localhost admin/admin bootstrap with token persistence to .env make its trust and secret-handling footprint higher than a simple reporting skill.
Confidence: 85%Severity: 56%
Audit Metadata