← Index

io.github.mshegolev/sonarqube-mcp

io.github.mshegolev/sonarqube-mcp·v0.1.0·Other

SonarQube MCP — projects, metrics, quality gate, issues, worst-metric ranking.

Trust verdict · v1 advisory · method
NOT YET SCREENEDno verdict on file

Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.

Own this server? Screen its description →

Environment variables
SONARQUBE_URL
required

SonarQube URL (e.g. https://sonar.example.com or https://sonarcloud.io)

SONARQUBE_TOKEN
requiredsecret

SonarQube authentication token (Bearer). Generate in: My Account → Security → Tokens.

SONARQUBE_SSL_VERIFY

Verify SSL certificates (true/false). Set to 'false' for self-signed certs.

MCP quality score · maturity, not trust · methodology
freshness
23
completeness
10
installability
25
documentation
15
stability
5
Alternatives in Other