Install
$ agentstack add skill-byerlikaya-claude-starter-kit-sonarqube-check ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
SonarQube Quality Gate (language-agnostic)
Zero-tolerance gate: a job does not close until the metrics below are clean. SonarQube analyzes more than 30 languages; the gate is the same whatever the language — only the scanner that runs it changes with the stack.
Gate (all mandatory)
- 0 Bugs · 0 Vulnerabilities · 0 Security Hotspots · 0 Code Smells
- Build 0 warnings / 0 errors
- Coverage above the threshold the project defines (especially on new code)
Running (scanner per stack)
First detect the project's build system, then pick the right scanner:
- Generic (JS/TS · Python · Go · PHP …) — SonarScanner CLI +
sonar-project.properties:
``bash sonar-scanner -Dsonar.host.url="" -Dsonar.token="$SONAR_TOKEN" ``
- .NET — a dedicated scanner, since MSBuild integration is required:
``bash dotnet sonarscanner begin /k:"" /d:sonar.host.url="" /d:sonar.cs.opencover.reportsPaths="**/coverage.opencover.xml" dotnet build --no-incremental dotnet test --collect:"XPlat Code Coverage" dotnet sonarscanner end ``
- Maven —
mvn verify sonar:sonar· Gradle —gradle sonar(SonarQube plugin).
Generate the coverage report per language (JS: lcov · Python: coverage.xml · Go: coverage.out · .NET: opencover) and wire it in with the corresponding sonar.*.reportPaths key.
Principles
- Clean as You Code: the gate is zero on new/changed code; legacy debt is handled separately, but no new debt is added.
- Security Hotspots are not ignored: each one is reviewed and either marked "safe" with a rationale or fixed.
- Finding → the relevant expert fixes it; no deferral, no "we'll look at it later".
DoD
- Quality Gate PASSED; green before PR/merge.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: byerlikaya
- Source: byerlikaya/claude-starter-kit
- License: MIT
- Homepage: https://www.npmjs.com/package/@byerlikaya/claude-starter-kit
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.