skills/felipeangeli/skills/sentry-cli/Gen Agent Trust Hub

sentry-cli

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to install the Sentry CLI by downloading and executing a script directly from Sentry's official domain via a shell pipe.
  • Evidence: curl https://cli.sentry.dev/install -fsS | bash in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: The skill references external installation sources for the Sentry CLI, including a dedicated install script and the npm registry.
  • Evidence: References to https://cli.sentry.dev/install and npm install -g sentry.
  • [COMMAND_EXECUTION]: The skill is designed to facilitate the execution of Sentry CLI commands, which interact with local and remote resources.
  • Evidence: Extensive list of sentry commands including auth, org, project, issue, and api.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Sentry issues and events. This data is untrusted and could contain malicious instructions meant to influence the AI agent's behavior.
  • Ingestion points: Data is ingested through commands like sentry issue list, sentry issue view, and sentry event view in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat issue content as untrusted data.
  • Capability inventory: The skill has the ability to perform authenticated network requests via sentry api and execute various CLI commands.
  • Sanitization: There is no evidence of sanitization or filtering of the retrieved issue or event data before it is presented to the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: https://cli.sentry.dev/install - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — sentry-cli