Daily chase-up for unreviewed SonarCloud security hotspots

By General Input

Every weekday morning, surface the security checks nobody has reviewed yet, file them in the right repository, and post your team one clear summary.

Integrations

  • SonarCloud
  • GitHub
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering

Every weekday at 9am, run on a cron trigger and chase down the SonarCloud security hotspots that are still sitting unreviewed, so they do not stay in the TO_REVIEW queue forever.

Start by finding the hotspots that need attention. Use the SonarCloud "Projects — Search" operation to list the projects in our organization, then use "Hotspots — Search" filtered to status TO_REVIEW for each project. For every hotspot that comes back, use "Hotspots — Show" to pull the full detail, including its security category, its file path and line, and the date it was raised.

Prioritize what you found. Rank by vulnerability probability, taking HIGH first, and within that favour anything that has been waiting more than 14 days. Keep the framing right: a hotspot is a judgement call rather than a confirmed bug, so the goal is to get a human to make a decision, not to claim something is broken.

For the top few, file GitHub issues. Before creating anything, call the GitHub "List Repository Issues" operation on the target repository and scan the open issues so you do not file a duplicate for a hotspot that has already been raised. Then use "Create an Issue" in the repository the hotspot belongs to. Each issue must state the file path, the line number, the security category (for example SQL injection or weak cryptography), a link back to the hotspot in SonarCloud, and the specific question the reviewer has to answer, such as whether the input reaching this query is already validated or whether this algorithm is acceptable for this data. Create at most five new issues per run so the backlog never gets flooded.

Finish by posting one consolidated summary to our security channel using the Slack Bot "Send a Message" operation. Include the total number of hotspots still awaiting review, name the repositories carrying the oldest unreviewed hotspots and how long they have been waiting, and list the issues you just created with links. Post a single message rather than one per hotspot. If there was nothing new worth filing, still post a short status so the team knows the queue was checked.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them