一键导入
sonar-fix
Find and fix SonarQube issues by severity
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Find and fix SonarQube issues by severity
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | sonar-fix |
| description | Find and fix SonarQube issues by severity |
Systematically identify and fix SonarQube issues, prioritized by severity.
The SonarQube project key for this repository is: mayflower_scry_53657c30-7823-4138-9fbf-78b92dfb99e9
Fetch All Open Issues:
Use mcp__sonarqube__search_sonar_issues_in_projects with:
["mayflower_scry_53657c30-7823-4138-9fbf-78b92dfb99e9"]Group and Prioritize: Sort issues by severity: BLOCKER -> CRITICAL -> HIGH -> MEDIUM -> LOW -> INFO
For Each Issue (starting with highest severity):
a. Show Issue Details:
b. Get Rule Details:
Use mcp__sonarqube__show_rule with the rule key (e.g., python:S1481)
This provides:
c. Read the Affected Code: Read the file and show context around the issue
d. Apply the Fix: Edit the file to resolve the issue following the rule guidance
e. Verify Fix: Run relevant tests or linters to ensure the fix doesn't break anything
Run Tests After Fixes:
uv run pytest tests/ -v --tb=short -m "not integration"
Run Linters:
uv run ruff check src/scry tests/
After fixing each issue (or batch of related issues), pause and report:
When the user wants to commit:
If an issue appears to be a false positive:
# noqa or inline suppression commentmcp__sonarqube__change_sonar_issue_status to mark as falsepositive or accept