{
  "name": "sonar-review",
  "version": "0.1.0",
  "description": "Run a Sonar scan against the just-changed code on the current branch and produce a structured compliance report — quality-gate verdict (PASS / FAIL), then severity-tagged findings (🟥 blocker / 🟧 critical / 🟨 major / ⚪ minor / ⚪ info) scoped to changed files, each with file:line, the Sonar rule ID, the category (bug / vulnerability / security hotspot / code smell), why it matters, and a concrete fix. Works against both **SonarQube server** (self-hosted) and **SonarCloud** (SaaS) — mode is detected from `sonar-project.properties`. Sister skill to `devils-advocate`, but enforces Sonar's rule catalog and the project's quality gate rather than a hand-rolled lens sweep. Use after writing code, before pushing or opening a PR, when the user says \"is this Sonar-compliant?\", \"run Sonar on this\", \"will the quality gate pass?\", or any pre-merge compliance check.",
  "entrypoint": "SKILL.md",
  "deps": {
    "npm": [],
    "pip": []
  },
  "env": {
    "required": [
      "SONAR_TOKEN"
    ],
    "optional": [
      "SONAR_HOST_URL"
    ]
  },
  "related": [
    "devils-advocate",
    "sonar-onboard"
  ],
  "tags": [
    "sonarqube",
    "sonarcloud",
    "sonar",
    "code-quality",
    "review",
    "quality-gate",
    "compliance",
    "security",
    "dev-workflow"
  ],
  "model": {
    "tier": "standard",
    "rationale": "Formats Sonar API findings into a report. The hard analysis is Sonar's; this is synthesis. Escalates on very large diffs."
  }
}
