Atlas / Skills / getsentry / Sentry Backend Bugs

Sentry Backend BugsCAUTION

skills/getsentry/sentry-backend-bugs

Developer-first error tracking and performance monitoring

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
NOASSERTION
Stars
44,873
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Vendored from https://github.com/getsentry/warden-sentry (.agents/skills/sentry-backend-bugs/).

If this skill needs updating, pull changes from that repository.

Read from source at commit 42a3375c14f5OBSERVED · 2026-09-29
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: sentry-backend-bugs
description: 'Review Sentry Python and Django changes for bug patterns drawn from real production issues. Use when reviewing a backend diff or PR, checking Warden findings, auditing the current branch, reviewing production-error patterns, or looking for common regressions in `src/` and `tests/`.'
allowed-tools: Read Grep Glob Bash
---

# Sentry Backend Bug Pattern Review

Find bugs in Sentry backend code by checking for the patterns that cause the most real production errors.

This skill encodes patterns from 638 real production issues (393 resolved, 220 unresolved, 25 ignored) generating over 27 million error events across 65,000+ affected users. These are not theoretical risks -- they are the actual bugs that ship most often, with known fixes from resolved issues.

## Scope

Review the code provided by the user, Warden, or the current branch diff. If the user does not provide a target, review the current branch diff. Start from the changed hunk or file, then read outward only as needed to confirm the behavior.

1. Analyze the changed code against the pattern checks below.
2. Use `Read` and `Grep` to trace data flow beyond the initial diff when needed. Follow function calls, callers, serializers, tasks, and ORM boundaries until the behavior is confirmed.
3. Report only **HIGH** and **MEDIUM** confidence findings.

| Confidence | Criteria                                                              | Action                       |
| ---------- | --------------------------------------------------------------------- | ---------------------------- |
| **HIGH**   | Traced the code path, confirmed the pattern matches a known bug class | Report with fix              |
| **MEDIUM** | Pattern is present but context may mitigate it                        | Report as needs verification |
| **LOW**    | Theoretical or mitigated elsewhere                                    | Do not report                |

## Step 1: Classify the Code

Determine what you are reviewing and load the relevant reference.

| Code Type                                                         | Load Reference                       |
| ----------------------------------------------------------------- | ------------------------------------ |
| ORM queries, model lookups, `.objects.get()`, FK access           | `references/missing-records.md`      |
| Type conversions, None handling, option reads, serializer returns | `references/null-and-type-errors.md` |
| Data input parsing, field lengths, request bodies, decompression  | `references/data-validation.md`      |
| `get_or_create`, `save()`, unique constraints, integer overflow   | `references/database-integrity.md`   |
| Integration webhooks, external API calls, SentryApp hooks         | `references/integration-errors.md`   |
| Dict iteration, shared state, concurrent access                   | `references/concurrency-bugs.md`     |
| Snuba queries, metric subscriptions, search filters               | `references/query-validation.md`     |
| Redirect URLs, URL construction, routing                          | `references/url-safety.md`           |

If the code spans multiple categories, load all relevant references.

## Step 2: Check for Top Bug Patterns

These are ordered by combined frequency and impact from real production data.

### Check 1: Metric Subscription Query Errors -- 113 issues, 3,035,640 events

Alert and metric subscriptions referencing tags or functions that do not exist in the target dataset. These fire continuously once created.

**Red flags:**

- Creating Snuba subscriptions with `SubscriptionData` using user-provided query strings without validation
- Referencing `transaction.duration` in p95/p99 functions on the metrics dataset (it is a string type there)
- Using custom tag names (e.g., `customerType`) as filter dimensions without checking they exist
- Calling `resolve_apdex_function` without verifying the dataset supports threshold parameters

**Safe patterns:**

- Validate query fields against dataset schema before subscription creation
- Wrap `_create_in_snuba` calls with try/except `SubscriptionError` and mark subscription as invalid
- Use `IncompatibleMetricsQuery` checks before building metric subscription queries

### Check 2: Missing Record / Stale Reference -- 81 issues, 1,403,592 events

Code calls `.get()` on a Django model assuming the record exists, but it has been deleted, merged, or never created.

**Red flags:**

- `Model.objects.get(id=some_id)` without try/except for `DoesNotExist`
- `Detector.objects.get(id=detector_id)` in workflow engine without handling deletion
- `Environment.objects.get(name=env_name)` in monitor/cron consumers
- `Subscription.objects.get(id=sub_id)` in billing tasks
- Using `Group.objects.get()` with IDs from Snuba query results (groups may be deleted/merged)
- Chained lookups where second `.get()` fails

**Safe patterns:**

- `Model.objects.filter(...).first()` with a None check
- try/except `DoesNotExist` that returns a graceful fallback (404, skip, log)
- Queryset `.exists()` check before `.get()`
- In API endpoints: return 404 for `DoesNotExist`, 400 for validation errors. Never suggest returning 500 intentionally.

**Not a bug — do not flag:**

- Infrastructure invariants: `.get()` enforcing a deployment precondition (e.g., "default org must exist in single-org mode") should crash — a 500 signals misconfiguration, not a code defect.
- Already validated by parent: If the endpoint base class validates the object (e.g., `OrganizationEndpoint` resolves the org), don't flag `.get()` on related records unless there's a genuine race or deletion window. Read the endpoint's parent class before reporting.
- Configuration lookups: Code that loads required config objects (`get_default()`, settings-based lookups) is expected to fail hard if the config is wrong.

### Check 3: Search Query Validation -- 57 issues, 2,001,330 events

InvalidSearchQuery from user-provided or subscription-stored qu
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
api-docs/.node-version
api-docs/.node-version
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 42a3375c14f5full audit observations/trust-audit/skill/getsentry__sentry-backend-bugs.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-2942a3375c14f5CAUTIONB89first audit
05

Questions

What does the Sentry Backend Bugs skill do?

Developer-first error tracking and performance monitoring

Is Sentry Backend Bugs safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Sentry Backend Bugs access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (42a3375c14f5), read on 2026-09-29. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement