sentry-instrument

Fail

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Instructions in references/setup-verification.md guide the agent to verify instrumentation using the Sentry MCP rather than deferring to the user to manually check a dashboard. This ensures the agent provides verified status reports, which is a functional requirement rather than a security bypass.
  • [EXTERNAL_DOWNLOADS]: The skill guides the installation of official Sentry SDKs and build tools across various ecosystems (npm, pip, composer, etc.). These are trusted resources from the verified vendor 'getsentry'.
  • [EXTERNAL_DOWNLOADS]: A reference file (references/sdks/svelte/session-replay.md) contains the domain analytics.third-party.com within a networkDetailDenyUrls configuration example. This demonstrates how to implement privacy-preserving filters to prevent data from being sent to third-party services.
  • [COMMAND_EXECUTION]: The skill uses official CLI tools like sentry-wizard and sentry-cli to automate the configuration of project settings and the upload of debug symbols.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 1, 2026, 03:30 PM
Security Audit — agent-trust-hub — sentry-instrument