sentry
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bundled Python script (
scripts/sentry_api.py) via shell commands to interact with the Sentry API. This is the primary mechanism for the skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface where user-provided inputs such as organization slugs, project names, and search queries are interpolated directly into shell command templates in
SKILL.md(e.g.,python3 "$SENTRY_API" list-issues --org {your-org}). - Ingestion points: User-controlled values for org slugs, project slugs, and query strings in
SKILL.mdcommands. - Boundary markers: Absent; user inputs are placed directly into command strings without explicit delimiters or escape warnings.
- Capability inventory: The skill has the ability to execute shell commands and perform network requests to the Sentry API via
scripts/sentry_api.py. - Sanitization: While the Python script uses
argparsefor internal argument handling, the instruction layer inSKILL.mddoes not specify shell-escaping for the interpolated variables. - [SAFE]: The skill handles sensitive authentication tokens securely by instructing the user to set the
SENTRY_AUTH_TOKENenvironment variable rather than hardcoding it or pasting it into the chat. - [SAFE]: Network activity is restricted to the well-known Sentry API domain (
https://sentry.io), and the skill includes logic inscripts/sentry_api.pyto redact PII such as email addresses and IP addresses from output.
Audit Metadata