sentry-svelte-sdk

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends using official Sentry installation methods, specifically npx @sentry/wizard@latest and npm install @sentry/sveltekit. Sentry is a well-known and established monitoring service.
  • [COMMAND_EXECUTION]: Phase 1 of the skill uses standard shell utilities such as cat, grep, and ls to inspect local project files like package.json and svelte.config.js. These commands are used solely for environment detection and do not execute arbitrary or dangerous code.
  • [DATA_EXFILTRATION]: Automated scanners flagged https://analytics.third-party.com as malicious. However, in references/session-replay.md, this URL is used exclusively as a placeholder within a networkDetailDenyUrls configuration. This is a security-positive example demonstrating how developers can prevent the SDK from sending sensitive session data to untrusted third-party domains.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 03:27 AM
Security Audit — agent-trust-hub — sentry-svelte-sdk