sentry-instrument

Fail

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Automated reputation scanners identified the URL 'https://analytics.third-party.com' and the file 'references/sdks/svelte/session-replay.md' as having a malicious reputation. In the documentation, this URL serves as a placeholder example for a domain to be blocked from recording.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a vulnerability surface where untrusted data from a Sentry MCP server enters the agent context, as noted in 'SKILL.md'. * Ingestion points: Event data and user comments retrieved from the Sentry MCP (SKILL.md). * Boundary markers: Behavioral instructions are provided to the agent to ignore instructions within the retrieved data. * Capability inventory: The execution environment provides capabilities for shell command execution and file system access. * Sanitization: Relies on the agent following safety instructions; no automated sanitization is implemented in the skill itself.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 31, 2026, 07:04 AM
Security Audit — agent-trust-hub — sentry-instrument