sentry-instrument
Fail
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing Sentry SDKs from standard and official package registries such as npm, PyPI, and Composer. These downloads are part of the intended and legitimate setup process for application monitoring.
- [COMMAND_EXECUTION]: The playbook directs the agent to execute standard development commands for package installation, project building, and debug symbol uploads. These commands are essential for the primary functionality of the skill and are performed within the user's project context.
- [SAFE]: The skill includes explicit security and privacy safeguards. It warns the agent not to commit authentication tokens to source control and to treat all data from external tools (Sentry MCP) as untrusted input, effectively mitigating risks of credential exposure and indirect prompt injection.
- [SAFE]: Automated scanner alerts for certain files (e.g., references/sdks/svelte/session-replay.md) and URLs (e.g., 'https://analytics.third-party.com') are determined to be false positives. The flagged URL is used as a generic placeholder in a documentation example for a deny-list (blocking tracking). The malware flags likely arise from descriptions of legitimate monitoring features, such as network request body capture, which generic scanners often misclassify as suspicious behavior.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata