sentry-automation

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server endpoint at https://rube.app/mcp to access the Sentry toolkit functionality.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from Sentry environments that can be influenced by external actors.
  • Ingestion points: Untrusted data such as stack traces, error messages, and issue tags are retrieved via tools like SENTRY_LIST_AN_ISSUES_EVENTS and SENTRY_RETRIEVE_AN_ISSUE_EVENT as described in SKILL.md.
  • Boundary markers: The instructions do not include delimiters or specific guidance to treat external Sentry data as potentially untrusted input.
  • Capability inventory: The skill possesses capabilities to modify Sentry configurations, including SENTRY_CREATE_PROJECT_RULE_FOR_ALERTS and SENTRY_CREATE_RELEASE_FOR_ORGANIZATION (found in SKILL.md).
  • Sanitization: There are no instructions for sanitizing or escaping the data retrieved from Sentry before it is used in subsequent agent steps or workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 05:34 AM
Security Audit — agent-trust-hub — sentry-automation