Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Sonar Rules

ASecurity

SonarLint / SonarQube / SonarJS rule catalogue (full 269-rule reference) plus per-language equivalents (golangci-lint, ruff, rubocop, errorlint, NullAway, clippy). Use when touching any code file to sweep against the highest-signal Sonar rules (S100, S107, S125, S138, S1192, S1481, S1854, S2068, S3358, S3776, S5547, S6571, S6606, S6594, S6644, S6759, S7755, S7773, S7780, S7781), apply per-file overrides for legitimate exceptions (test files, SSRF validators, domain nouns), and configure eslin...

12 stars
0 votes
0 copies
0 views
Added 10/6/2026
ai-agentsjavascripttypescriptpythonrustgojavaphpswiftc#sql

Works with

cliapi

Security Analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned 10/6/2026

$npx -y skills add Nmor/the-council --skill sonar-rules --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sonar Rules?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Sonar Rules
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nmor-sonar-rules-the-council/badge)](https://www.skillsdirectory.com/skills/nmor-sonar-rules-the-council)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: sonar-rules
description: SonarLint / SonarQube / SonarJS rule catalogue (full 269-rule reference) plus per-language equivalents (golangci-lint, ruff, rubocop, errorlint, NullAway, clippy). Use when touching any code file to sweep against the highest-signal Sonar rules (S100, S107, S125, S138, S1192, S1481, S1854, S2068, S3358, S3776, S5547, S6571, S6606, S6594, S6644, S6759, S7755, S7773, S7780, S7781), apply per-file overrides for legitimate exceptions (test files, SSRF validators, domain nouns), and configure eslint-plugin-sonarjs at sonarjs/recommended.
paths:
  - "**/*.ts"
  - "**/*.tsx"
  - "**/*.js"
  - "**/*.jsx"
  - "**/*.mjs"
  - "**/*.cjs"
  - "**/*.mts"
  - "**/*.cts"
  - "**/*.py"
  - "**/*.go"
  - "**/*.rb"
  - "**/*.rs"
  - "**/*.java"
  - "**/*.kt"
  - "**/*.kts"
  - "**/*.swift"
  - "**/*.dart"
  - "**/*.cs"
  - "**/*.c"
  - "**/*.cpp"
  - "**/*.cc"
  - "**/*.cxx"
  - "**/*.h"
  - "**/*.hpp"
  - "**/*.lua"
  - "**/*.php"
  - "**/*.vue"
  - "**/.eslintrc*"
  - "**/eslint.config.*"
  - "**/.sonarcloud.properties"
  - "**/sonar-project.properties"
disable-model-invocation: true
---

# SonarLint / SonarQube Checks (Global Default)

> **Size budget: 25 KB.** Check: wc -c. Gate: node ~/.claude/scripts/token-budget.mjs --check
>
> Migrated 2026-06-02 from `~/.claude/rules-library/common/sonarlint-checks.md` as part of the
> lazy-rules-loading plan. Phase H will delete the original to close the eager-load loop.

## Standards Cited

- **SonarSource Rule Specifications** (rules.sonarsource.com) — canonical authority for every
  `S<number>` rule in this catalog (S100, S107, S125, S138, S1192, S3776, S6571, S6594, S6606, etc.)
- **CWE-94** — Improper Control of Generation of Code (S2076 / S6587 + family)
- **CWE-89** — SQL Injection (S2077 / S3649)
- **CWE-79** — Cross-Site Scripting (S5247 / S6299)
- **CWE-798** — Hard-coded Credentials (S2068)
- **CWE Top 25** Most Dangerous Software Weaknesses (mitre.org/cwe) — Sonar rule severity ladder
  maps to CWE
- **OWASP Top 10 A03:2021** Injection — S2076 / S2077 / S5247 cluster
- **OWASP Top 10 A07:2021** Identification + Authentication Failures — S2068 / S5547 cluster
- **OWASP ASVS 4.0.3 §5** Validation — S2755 (XXE) / S4502 (CSRF disabled)
- **ISO/IEC 25010:2011** Quality Model — Sonar maintainability / reliability / security ratings
  derive from this
- **NIST SP 800-53** SI-10 Information Input Validation — Sonar's injection-class rules align

> This rule fires on every file. Whenever Claude touches code in any project — new or legacy, with
> or without a project-level Sonar setup — it must verify the file against the rules below and fix
> every violation in the touched file (Rule 5: Zero Tolerance).
>
> **Threshold-tightening note**: `extreme-lint-policy.md` overrides the Sonar default thresholds
> globally. Specifically: cognitive complexity (S3776) cap is **10** (not 15), function lines (S138)
> cap is **80** (not 200), function parameters (S107) cap is **5** (not 7), file lines (S104) cap is
> **500** (not 1000), nested control-flow depth (S134) cap is **3** (not 4), boolean expression
> operators (S1067) cap is **2** (not 3), magic-number tolerance (S109) allows only `0, 1, -1, 2`.
> This file lists the Sonar rule IDs + canonical defaults; the strict overrides in
> `extreme-lint-policy.md` are what the project enforces.

## Why this is global

SonarLint is a quality safety net that catches the same bugs across every language. Running it as a
global default means:

- Every project benefits, even ones that don't have SonarLint installed locally.
- Claude doesn't wait to be asked — it sweeps proactively, in line with
  `feedback_check_sonar_proactively`.
- The Council's verification-loop has a concrete checklist instead of "looks fine."

The user has SonarLint enabled in their VS Code setup with the highest-signal rules listed here.
ErrorLens surfaces these inline. Claude's job is to address them before declaring a task done.

## Where each topic lives

This file is the routing table. Read the reference file for the topic in hand;
do not carry the whole catalogue to answer one question.

| Topic | Reference file |
| ---- | ---- |
| Wiring SonarJS into a TypeScript / JavaScript repo (mandatory step); stylistic rules to disable; per-file overrides for legitimate exceptions; Eqeqeq + null; Vue / React projects; ESLint guardrails for every TS/JS project | [`references/eslint-setup.md`](references/eslint-setup.md) |
| Mandatory checks on every touched file — the comprehensive TypeScript / JavaScript rule reference (string / regex idioms, style / idiom, type / control-flow, error handling, security, suppression / meta, numerical) and the cross-language quick table | [`references/typescript-rules.md`](references/typescript-rules.md) |
| Sweep procedure; Don't silence — fix; Output expectation | [`references/sweep-and-reporting.md`](references/sweep-and-reporting.md) |
| Cross-language Sonar coverage — Go (SonarGo / golangci-lint), Python (SonarPy / ruff), Java (SonarJava), C# (SonarC#), Swift (SwiftLint), Rust (clippy) | [`references/cross-language.md`](references/cross-language.md) |
| Full SonarJS catalog — every rule, all 269, with ESLint rule name and `sonarjs/recommended` default | [`references/sonarjs-catalog.md`](references/sonarjs-catalog.md) |

## Learning hooks

Per `~/.claude/rules/common/continuous-learning-mandate.md`:

**Signals to watch**:

- New TS/JS repo opened without `eslint-plugin-sonarjs` wired (mandatory-step weakening)
- SonarLint IDE warnings ignored / dismissed across multiple sessions on the same project
- Per-line `// eslint-disable` / `// @ts-ignore` introduced to silence a Sonar rule (rule-violation
  shortcut)
- File-level grep sweep skipped on touched-file audit (sweep procedure step 2 weakening)
- Recurring rule fires in the same file (e.g., S1192 fires 3× per quarter on `apiClient.ts`) — the
  underlying pattern needs structural fix
- Threshold-tightening note out of sync with `extreme-lint-policy.md` (canonical thresholds drift)
- Cross-language equivalents missing on touched files (Go / Python / Java / C# / Swift / Rust
  per-language equivalents skipped)
- Stylistic disable-list grows with rules that produce real bugs (over-disabling — recurrence audit
  needed)

**Refinement candidates**:

- New rule row when a new SonarJS rule ships (the catalog regularly grows; add columns + fix
  recipes)
- Tightening of the disabled-rules list when a previously-stylistic rule starts catching real bugs
- New cross-language entry when a recurring shape gains a Sonar equivalent in another language
  (e.g., SonarRust ships)
- Promotion of a per-file Sonar exception to a project-wide allowlist with documented rationale
  (e.g., SSRF validator file exempt from S1313 by design)

Attribution

NmorNmor
View sourceSee grades on GitHubMore from Nmor →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →