sentry-cli
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to install the Sentry CLI by downloading and executing a script directly from Sentry's official domain via a shell pipe.
- Evidence:
curl https://cli.sentry.dev/install -fsS | bashinSKILL.md. - [EXTERNAL_DOWNLOADS]: The skill references external installation sources for the Sentry CLI, including a dedicated install script and the npm registry.
- Evidence: References to
https://cli.sentry.dev/installandnpm install -g sentry. - [COMMAND_EXECUTION]: The skill is designed to facilitate the execution of Sentry CLI commands, which interact with local and remote resources.
- Evidence: Extensive list of
sentrycommands includingauth,org,project,issue, andapi. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Sentry issues and events. This data is untrusted and could contain malicious instructions meant to influence the AI agent's behavior.
- Ingestion points: Data is ingested through commands like
sentry issue list,sentry issue view, andsentry event viewinSKILL.md. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat issue content as untrusted data.
- Capability inventory: The skill has the ability to perform authenticated network requests via
sentry apiand execute various CLI commands. - Sanitization: There is no evidence of sanitization or filtering of the retrieved issue or event data before it is presented to the agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://cli.sentry.dev/install - DO NOT USE without thorough review
Audit Metadata