No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by SonarSource · MCP Server · ★ 654
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is sonarqube-mcp-server safe to install? View the security audit →
SonarQube MCP Server The SonarQube MCP Server is a Model Context Protocol (MCP) server that enables seamless integration with SonarQube Server or Cloud for code quality and security. It also supports the analysis of code snippet directly within the agent context. Quick setup The simplest method is to rely on our container image hosted at mcp/sonarqube. Read below if you want to build it locally. Note: While the examples below use , any OCI-compatible container runtime works (e.g., Podman, nerdctl). Simply replace with your preferred tool. Security Best Practices 🔒 Important: Your SonarQube token is a sensitive credential. Follow these security practices: When using CLI commands: Avoid hardcoding tokens in command-line arguments - they get saved in shell history Use environment variables - set tokens in environment variables before running commands When using configuration files: Never commit tokens to version contr
| Stars | 654 |
| Forks | 99 |
| Language | Java |
| Category | MCP Server |
| Quality Score | 70.0832567166283/100 |
| Open Issues | 16 |
| Last Updated | 2026-09-24 |
| Created | 2025-04-30 |
| Platforms | java, mcp |
| Est. Tokens | ~28k |
These tools work well together with sonarqube-mcp-server for enhanced workflows:
Looking for a sonarqube-mcp-server alternative? If you're comparing sonarqube-mcp-server with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Security scanner for AI agents, MCP servers and agent skills.
Shrimp Task Manager is a task tool built for AI Agents, emphasizing chain-of-thought, reflection, and style co
Create AI Agents in a No-Code Visual Builder or TypeScript SDK with full 2-way sync. For shipping AI assistant
Just a Better Chatbot. Powered by Agent & MCP & Workflows.
A security scanner for your LLM agentic workflows
Ultimate Context Engineering Infrastructure, starting from MCPs and Integrations
Explore other popular mcp server tools:
sonarqube-mcp-server is Official SonarQube MCP Server for code quality and security in AI agents. It is categorized as a MCP Server with 654 GitHub stars.
sonarqube-mcp-server is primarily written in Java. It covers topics such as agent, ai, code-quality.
You can find installation instructions and usage details in the sonarqube-mcp-server GitHub repository at github.com/SonarSource/sonarqube-mcp-server. The project has 654 stars and 99 forks, indicating an active community.
The top alternatives to sonarqube-mcp-server on Agent Skills Hub include agent-scan, mcp-shrimp-task-manager, agents. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: