Official agent skill

Sentry Security

by getsentry in getsentry/sentry

Sentry-specific security review based on real vulnerability history.

OfficialCustom licenceAuto-check: notesSecurity

Install Sentry Security

skills CLI
$ npx skills add getsentry/sentry --skill sentry-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/sentry sentry-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/sentry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sentry-security .claude/skills/sentry-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sentry-security
GitHub stars
45k
Token cost
~2.3k tokens
SKILL.md length
920 words
Files
8 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Custom licence

At a glance

Sentry-specific security review based on real vulnerability history.

  • Works in 4 steps: Classify the Code → Check for the Top 6 Vulnerability Classes → Trace the Full Enforcement Chain → …
  • Reviewing Sentry endpoints
  • SKILL.md covers Scope, Step 1: Classify the Code, Step 2: Check for the Top 6… and Step 3: Trace the Full…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sentry Security is an agent skill from getsentry/sentry, published by the product's own GitHub organization. Sentry-specific security review based on real vulnerability history. Use when reviewing Sentry endpoints, serializers, or views for security issues. Trigger keywords: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint".

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `README.md`, `references/endpoint-patterns.md` and `references/enforcement-layers.md`).

It sits in Security, covering Security review, Web application vulnerabilities and Authorization and RBAC. It works with Sentry. The repository describes itself as: Developer-first error tracking and performance monitoring.

When your agent uses it

  • Reviewing Sentry endpoints
  • Views for security issues
  • Keywords: sentry security review
  • Access control review

Example prompts

  • “sentry security review”
  • “check for IDOR”
  • “access control review”
  • “/sentry-security”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Classify the Code
  2. Check for the Top 6 Vulnerability Classes
  3. Trace the Full Enforcement Chain
  4. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 87d1203. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sentry Security loads about 2.3k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 77 tokens; SKILL.md has 920 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 920 words (~2,287 tokens).

“Find security vulnerabilities in Sentry code by checking for the patterns that have caused real vulnerabilities in this codebase.”

— opening of SKILL.md by getsentry, Custom licence
name
sentry-security
allowed-tools
Read, Grep, Glob, Bash

Read the full SKILL.md on GitHub

Files

SKILL.md and 7 other files (references) in .agents/skills/sentry-security of getsentry/sentry.

  • SKILL.md
  • README.md
  • references/endpoint-patterns.md
  • references/enforcement-layers.md
  • references/output-sanitization.md
  • references/privilege-escalation.md
  • references/serializer-patterns.md
  • references/token-lifecycle.md

Open the folder on GitHubat commit 87d1203

Compare with similar skills

Sentry Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sentry Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sentry Security this skillgetsentry/sentry45k—~2.3kAutomated safety check: NotesCustom licence
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Security Checkgocronx-team/gocron808—~690Automated safety check: PassMIT
Warden Security ReviewUsefulSoftwareCo/executor4.1k—~1.3kAutomated safety check: PassMIT
Security Reviewlangfuse/langfuse35k—~1.4kAutomated safety check: PassCustom licence
Security ConvexIgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNone

Similar skills

  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Check

    gocronx-team/gocron

    Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

    808 GitHub stars~690 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Warden Security Review

    UsefulSoftwareCo/executor

    Run Warden security scans in this repo using Sentry's warden-skills.

    4.1k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    35k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Security Convex

    IgorWarzocha/Opencode-Workflows

    Review Convex security audit patterns for authentication and authorization.

    122 GitHub stars~3.1k tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes

More from getsentry/sentry

All 29 skills in this repo
  • Scraps Review

    getsentry/sentry

    Official

    Filter large Sentry Scraps design-system migration PRs for review by separating mechanical import-path changes, generated baseline updates, snapshot mocks, and pure renames from substantive…

    45k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Analytics

    getsentry/sentry

    Official

    Instrument and discover analytics events in Sentry's frontend UI.

    45k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Hybrid Cloud Outboxes

    getsentry/sentry

    Official

    Guide for creating and maintaining outbox-based eventually consistent operations in Sentry.

    45k GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Hybrid Cloud Rpc

    getsentry/sentry

    Official

    Guide for creating, updating, and deprecating hybrid cloud RPC services in Sentry.

    45k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Hybrid Cloud Test Gen

    getsentry/sentry

    Official

    Generate hybrid cloud tests for the Sentry codebase. An agent skill from getsentry/sentry.

    45k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Lint Fix

    getsentry/sentry

    Official

    Fix violations of an eslintPluginScraps rule across the codebase.

    45k GitHub stars~1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Sentry Security

What does Sentry Security do?

Sentry-specific security review based on real vulnerability history. Sentry Security is an agent skill from getsentry/sentry, published by the product's own GitHub organization. Sentry-specific security review based on real vulnerability history.

When should I use Sentry Security?

Sentry Security fits situations like: reviewing Sentry endpoints; views for security issues; keywords: sentry security review; access control review.

How do I install Sentry Security in Claude Code?

Run `npx skills add getsentry/sentry --skill sentry-security -a claude-code`. Or copy the skill folder (.agents/skills/sentry-security in getsentry/sentry) into .claude/skills/sentry-security in your project. Claude Code loads it when a task matches its description.

How do I install Sentry Security in Codex?

Run `npx skills add getsentry/sentry --skill sentry-security -a codex`. Or copy the skill folder (.agents/skills/sentry-security in getsentry/sentry) into .agents/skills/sentry-security in your project. Codex loads it when a task matches its description.

Can I use Sentry Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/sentry --skill sentry-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sentry-security, .gemini/skills/sentry-security, .github/skills/sentry-security and .opencode/skills/sentry-security in your project.

What does Sentry Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Sentry Security is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Sentry Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sentry Security safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sentry Security use?

Sentry Security has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Sentry Security use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.9k tokens, read only when the agent opens those files.

What are the alternatives to Sentry Security?

Skills that share tags, products or a category with Sentry Security: Strix Code Vulnerability Scan (usestrix/strix, 67k stars), Security Check (gocronx-team/gocron, 808 stars), Warden Security Review (UsefulSoftwareCo/executor, 4.1k stars) and Security Review (langfuse/langfuse, 35k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sentry Security?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/sentry, which has 45,495 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 7, 2026.

Source: getsentry/sentry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.