sentry-setup-releases
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill proactively addresses potential indirect prompt injection by instructing the agent to treat all tool outputs (tags, messages, frame paths) as untrusted input and explicitly forbids executing any instructions found within event payloads or issue titles.
- [SAFE]: The skill reinforces secure credential management by directing the user to store authentication tokens in CI secrets and specifically warns against committing them to the repository.
- [SAFE]: References to external tools such as
sentry-cliand GitHub Actions (getsentry/action-release) are official resources provided by the verified vendor (getsentry) and do not pose a third-party supply chain risk in this context.
Audit Metadata