Atlas / Skills / getsentry / Sentry Javascript Bugs

Sentry Javascript BugsCAUTION

skills/getsentry/sentry-javascript-bugs

Developer-first error tracking and performance monitoring

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
NOASSERTION
Stars
44,873
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Vendored from https://github.com/getsentry/warden-sentry (.agents/skills/sentry-javascript-bugs/).

If this skill needs updating, pull changes from that repository.

Read from source at commit 42a3375c14f5OBSERVED · 2026-09-29
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: sentry-javascript-bugs
description: 'Review Sentry React and TypeScript changes for bug patterns drawn from real production issues. Use when reviewing a frontend diff or PR, checking Warden findings, auditing the current branch, reviewing production-error patterns, or looking for common regressions in `static/`.'
allowed-tools: Read Grep Glob Bash
---

# Sentry JavaScript Frontend Bug Pattern Review

Find bugs in Sentry frontend code by checking for the patterns that cause the most real production errors.

This skill encodes patterns from 428 real production issues (201 resolved, 130 ignored, 97 unresolved) generating over 524,000 error events across 93,000+ affected users. These are not theoretical risks -- they are the actual bugs that ship most often, with known fixes from resolved issues.

## Scope

Review the code provided by the user, Warden, or the current branch diff. If the user does not provide a target, review the current branch diff. Start from the changed hunk or file, then read outward only as needed to confirm the behavior.

1. Analyze the changed code against the pattern checks below.
2. Use `Read` and `Grep` to trace data flow beyond the initial diff when needed. Follow component props, hook return values, API response shapes, and state transitions until the behavior is confirmed.
3. Report only **HIGH** and **MEDIUM** confidence findings.

| Confidence | Criteria                                                              | Action                       |
| ---------- | --------------------------------------------------------------------- | ---------------------------- |
| **HIGH**   | Traced the code path, confirmed the pattern matches a known bug class | Report with fix              |
| **MEDIUM** | Pattern is present but context may mitigate it                        | Report as needs verification |
| **LOW**    | Theoretical or mitigated elsewhere                                    | Do not report                |

## Step 1: Classify the Code

Determine what you are reviewing and load the relevant reference.

| Code Type                                                               | Load Reference                          |
| ----------------------------------------------------------------------- | --------------------------------------- |
| Null/undefined property access, optional chaining, object destructuring | `references/null-reference-errors.md`   |
| Dashboard widgets, chart visualization, widget URL generation           | `references/dashboard-widget-errors.md` |
| Trace views, span details, trace tree rendering                         | `references/trace-view-errors.md`       |
| API calls, response handling, error states, fetch wrappers              | `references/api-response-handling.md`   |
| React hooks, context providers, render loops, component lifecycle       | `references/react-lifecycle-errors.md`  |
| AI Insights, LLM prompt parsing, gen_ai span data                       | `references/ai-insights-parsing.md`     |
| Array operations, date/time values, numeric formatting                  | `references/range-and-bounds-errors.md` |

If the code spans multiple categories, load all relevant references.

## Step 2: Check for Top Bug Patterns

These are ordered by combined frequency and impact from real production data.

### Check 1: Null/Undefined Property Access -- 158 issues, 46,337 events

Code accesses a property on a value that may be null or undefined. This is the single most common bug pattern in the Sentry frontend.

**Red flags:**

- Accessing `.id`, `.slug`, `.name`, `.type`, `.match`, `.length`, `.charCodeAt` without null checks
- Using `object.property` instead of `object?.property` on data from API responses
- Passing API response data directly to utility functions without null validation
- Accessing DOM element properties from `querySelector` or `useRef` without checking if the element exists
- Destructuring objects from hooks/stores that may return null during loading states
- Calling `.dispatchEvent()` on elements that have been unmounted

**Safe patterns:**

- Optional chaining: `obj?.property?.nested`
- Default values: `const value = obj?.field ?? defaultValue`
- Null guards before function calls: `if (data) { parser.parse(data); }`
- Early returns for null/undefined parameters in utility functions

### Check 2: Dashboard Widget Input Validation -- 6 issues, 90,482 events

Widget visualization components throw when receiving data in unexpected formats.

**Red flags:**

- Rendering chart components without checking if data contains plottable values
- Calling `getWidgetExploreUrl()` for widget types that do not support multiple queries
- Passing undefined `field` values to `parseFunction()` or similar field parsers
- Not handling empty API responses in widget data fetchers

**Safe patterns:**

- Validate data shape before rendering: `if (!hasPlottableValues(data)) return <EmptyState />`
- Check widget query count before generating explore URLs
- Guard field parsers: `if (!field) return null`

### Check 3: Trace View Data Integrity -- 12 issues, 328,482 events

The trace tree renderer and trace detail views encounter data that violates structural assumptions.

**Red flags:**

- Building trace trees without cycle detection (or detecting cycles but not handling them gracefully)
- Looking up projects by ID from span data without checking if the project is accessible
- Generating trace links without validating `traceSlug` is non-empty
- Using `captureException` in render paths without deduplication (fires every render cycle)

**Safe patterns:**

- Break cycles by detaching cyclic nodes as orphan roots
- Validate traceSlug before generating links: `if (!traceSlug) return fallbackLink`
- Deduplicate error captures using a ref: `if (!capturedRef.current) { captureException(...); capturedRef.current = true; }`
- Check project access before rendering span details

### Check 4: API Response Shape Assumptions -- 31 issues, 24,019 event
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
api-docs/.node-version
api-docs/.node-version
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 42a3375c14f5full audit observations/trust-audit/skill/getsentry__sentry-javascript-bugs.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-2942a3375c14f5CAUTIONB89first audit
05

Questions

What does the Sentry Javascript Bugs skill do?

Developer-first error tracking and performance monitoring

Is Sentry Javascript Bugs safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Sentry Javascript Bugs access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (42a3375c14f5), read on 2026-09-29. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement