skills/letta-ai/skills/sentry/Gen Agent Trust Hub

sentry

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled Python script (scripts/sentry_api.py) via shell commands to interact with the Sentry API. This is the primary mechanism for the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface where user-provided inputs such as organization slugs, project names, and search queries are interpolated directly into shell command templates in SKILL.md (e.g., python3 "$SENTRY_API" list-issues --org {your-org}).
  • Ingestion points: User-controlled values for org slugs, project slugs, and query strings in SKILL.md commands.
  • Boundary markers: Absent; user inputs are placed directly into command strings without explicit delimiters or escape warnings.
  • Capability inventory: The skill has the ability to execute shell commands and perform network requests to the Sentry API via scripts/sentry_api.py.
  • Sanitization: While the Python script uses argparse for internal argument handling, the instruction layer in SKILL.md does not specify shell-escaping for the interpolated variables.
  • [SAFE]: The skill handles sensitive authentication tokens securely by instructing the user to set the SENTRY_AUTH_TOKEN environment variable rather than hardcoding it or pasting it into the chat.
  • [SAFE]: Network activity is restricted to the well-known Sentry API domain (https://sentry.io), and the skill includes logic in scripts/sentry_api.py to redact PII such as email addresses and IP addresses from output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — sentry