MCP server / Sonar

SonarQube MCP Server for Codex

Official SonarQube MCP Server for code quality and security in AI agents.

Docs reviewedChecked 2026-09-20Runtime not tested

What it adds

Official SonarQube MCP Server for code quality and security in AI agents

agentaisonarqubecode-qualitysecuritystatic-analysis

Get set up

  1. Run the install command below to register the server with Codex.
  2. Restart Codex or start a new thread so the tools load.
Read the installation source

Before you install

  • YOUR_USER_TOKEN
  • YOUR_SERVER_URL
  • SONAR_USER_TOKEN
  • COPILOT_MCP_SONARQUBE_TOKEN
  • COPILOT_MCP_SONARQUBE_URL

Compatibility & limitations

Documented for ChatGPT desktop app, Codex CLI, Codex IDE extension

Cursor: Not confirmed for Cursor.

    This listing is based on source documentation. We have not installed or runtime-tested this asset.

    How it fits together

    Security Best Practices · SkillPerform language and framework specific security best-practice reviews and suggest improvements.Security Ownership Map · SkillAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export...Security Threat Model · SkillRepository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a...

    Sources & provenance

    Reviewed 2026-09-20. Source revision: main (mutable; commit not pinned).