Skip to main content
bash TV

SonarQube + OpenAI: Agentic Development — Killian Carlsen-Phelan, Sonar

AI Engineer

63 views11 Oct 2026

YouTube

A tiny Python project contains a hardcoded API key, a SQL injection path and other deliberately planted issues. Killian Carlsen-Phelan runs it through SonarQube, brings the findings into Codex and asks the agent to fix the vulnerable query. The scan follows user controlled input into database execution; the repair replaces string interpolation with a parameterized query. A verification hook checks the edited code again, putting the security feedback inside the coding loop rather than leaving it for a later failed build or review. The workshop develops Sonar's guide, verify and solve workflow through a live setup of SonarQube Cloud, its CLI, plugin and MCP server. A secrets detection hook blocks a fake credential in a prompt, while an issue listing skill gives the agent evidence from the project dashboard. Context augmentation supplies coding guidance before generation, and agentic analysis checks edits as they happen. The opening OpenAI introduction separates execution containment from artifact correctness and defines completion through a reviewable change and independent evidence. Questions explore how the hooks can be bypassed, which steps run locally or in a container, and which features depend on organizational access. Killian finishes by adding a new database operation under the same verification loop, showing how the setup supports both fixing existing issues and checking new work. Speaker info: - https://www.linkedin.com/in/kcarlsen2 - https://github.com/SonarSource/sonarqube-cli Timestamps: 0:00 - Completion requires evidence 2:44 - Containment and correctness 3:56 - Feedback inside the agent loop 5:46 - Killian and the workshop setup 8:17 - Guide, verify, and solve 9:40 - Move verification into the IDE 12:11 - Provision the sample project 14:06 - Deliberately planted issues 16:14 - Secrets and SQL injection 18:05 - Follow the vulnerable data flow 20:09 - Inspect the SonarQube dashboard 21:52 - Install the Codex plugin 23:19 - Authenticate and integrate the CLI 25:21 - Hooks, skills, and configuration 27:12 - Block a fake secret 28:08 - Hook boundaries and bypass questions 29:00 - MCP and issue listing 32:10 - Local configuration and Docker 34:12 - Access and feature entitlements 35:09 - Fix the SQL injection finding 37:04 - Verify the parameterized query 38:28 - Add a new database operation 40:34 - Community resources and wrap up

Join the discussion

Sign in to join the discussion

Sign in