Atlas / Skills / getsentry / Sentry Security

Sentry SecurityCAUTION

skills/getsentry/sentry-security

Developer-first error tracking and performance monitoring

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
NOASSERTION
Stars
44,873
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Sentry-specific security review skill synthesized from real vulnerability history.

Source Commits

This skill was synthesized by analyzing 37 security patches on master from 2025-02-18 to 2026-02-18. The patterns, examples, and checklists in the skill are derived directly from these fixes.

IDOR / Cross-Org Data Access (9)

Missing Authorization / Access Checks (10)

Read from source at commit 42a3375c14f5OBSERVED · 2026-09-29
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: sentry-security
description: 'Sentry-specific security review based on real vulnerability history. Use when reviewing Sentry endpoints, serializers, or views for security issues. Trigger keywords: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint".'
allowed-tools: Read Grep Glob Bash
---

# Sentry Security Review

Find security vulnerabilities in Sentry code by checking for the patterns that have caused real vulnerabilities in this codebase.

This skill is Sentry-specific. It encodes patterns from 37 real security patches shipped in the last year — not generic OWASP theory.

## Scope

Review the code provided by the user (file, diff, or endpoint). Research the codebase as needed to build confidence before reporting.

Report only **HIGH** and **MEDIUM** confidence findings. Do not report theoretical issues.

| Confidence | Criteria                                   | Action                       |
| ---------- | ------------------------------------------ | ---------------------------- |
| **HIGH**   | Traced the flow, confirmed no check exists | Report with fix              |
| **MEDIUM** | Check may exist but could not confirm      | Report as needs verification |
| **LOW**    | Theoretical or mitigated elsewhere         | Do not report                |

## Step 1: Classify the Code

Determine what you're reviewing and load the relevant reference.

| Code Type                                | Load Reference                       |
| ---------------------------------------- | ------------------------------------ |
| API endpoint (inherits from `*Endpoint`) | `references/endpoint-patterns.md`    |
| Serializer or form field                 | `references/serializer-patterns.md`  |
| Email template or HTML rendering         | `references/output-sanitization.md`  |
| Token, OAuth, or session handling        | `references/token-lifecycle.md`      |
| Role or permission logic                 | `references/privilege-escalation.md` |

If the code spans multiple categories, load all relevant references.

**Always load** `references/enforcement-layers.md` — it documents where security checks can legitimately live in Sentry's request lifecycle. A check in any layer counts as enforcement.

## Step 2: Check for the Top 6 Vulnerability Classes

These are ordered by frequency from the last year of real patches.

### Check 1: Cross-Org Object Access (IDOR) — 9 patches last year

The most common vulnerability. An endpoint accepts an ID from the request but does not scope the query by the organization from the URL.

**Trace this flow for every ID that comes from the request:**

```
1. Where does the ID enter? (query param, request body, URL kwarg)
2. Where is it used in an ORM query?
3. Between (1) and (2), is the query scoped by organization_id or project_id
   from the URL (NOT from the request body)?
```

**Red flags:**

- `Model.objects.get(id=request.data["something_id"])` — no org scope
- `Model.objects.filter(id=request.GET["id"])` — no org scope
- `project_id` from request body/query used directly without `Project.objects.filter(id=pid, organization_id=organization.id)`
- Endpoint inherits `OrganizationEndpoint` but handler method does not accept or use the `organization` parameter

**Safe patterns:**

- Query includes `organization_id=organization.id` where `organization` comes from `convert_args()`
- Uses `self.get_projects()` which scopes by org internally
- Object is fetched via URL kwargs resolved by `convert_args()`
- Unscoped query is a guard that only raises an error (never returns data), AND
  a downstream query in the same flow IS org-scoped and raises the same error —
  no differential behavior means no information leak

### Check 2: Missing Authorization Checks — 10 patches last year

An endpoint or serializer performs a sensitive operation without verifying the user has permission.

**Check:**

- Does the endpoint inherit from the right base class? (`OrganizationEndpoint`, `ProjectEndpoint`, etc.)
- Does it declare `permission_classes`? If not, it inherits the base class default — verify that's appropriate.
- For serializer fields that reference other objects: do they validate the user can access those objects?
- For Django views (not DRF): is there a `@login_required` or equivalent?

### Check 3: Privilege Escalation / Role Abuse — 3 patches last year

A user can assign ownership, modify roles, or escalate access beyond what their role allows.

**Check:**

- Owner/assignee fields: uses `OwnerActorField` (validates membership), NOT `ActorField` (allows any actor)
- Role modification endpoints: verify the requesting user's role is >= the target role
- Team assignment: verify the user is a member of the target team (or has `team:admin`)

### Check 4: Token / Session Security — 5 patches last year

Token lifecycle gaps that allow unauthorized access.

**Check:**

- Token refresh: is the application's active status checked before granting a refresh?
- Org-level tokens: is `organization_id` required and validated?
- Member status: is the member's enabled/disabled status checked before granting tokens?
- Impersonation: are impersonated sessions rate-limited?

### Check 5: Output Sanitization (XSS/HTML Injection) — 4 patches last year

User-controlled strings rendered unsafely in emails, markdown, or HTML.

**Check:**

- User display names, team names, org names used in email templates: are they sanitized?
- Markdown rendering: is custom CSS or HTML allowed through?
- `format_html()` vs string concatenation in templates
- `mark_safe()` called on user input

### Check 6: Auth/MFA Gaps — 3 patches last year

Authentication state inconsistencies.

**Check:**

- When removing an authenticator: are recovery codes cleaned up?
- CSRF token handling: is it synced across tabs/windows?
- Session invalidation: does removing auth factors properly invalidate sessions?

**If no checks produced a potential finding, stop and re
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (6)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
api-docs/.node-version
api-docs/.node-version
Why it matters. link not followed
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/enforcement-layers.md:87
- **Centralized enforcement** — the check runs in a permission class inherited by all endpoints within the affected scope. The credential cannot reach any endpoint that lacks the check. Classify as **
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/enforcement-layers.md:90
**Example (LOW — centralized):** OAuth authorize view issues a token to a `member-limit:restricted` member. The token exists, but `is_member_disabled_from_limit()` in `OrganizationPermission.determine
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/enforcement-layers.md:92
**Example (MEDIUM — scattered):** A token is issued without checking X, and X is only validated in specific endpoint subclasses (not the base). Some endpoints may not inherit the check. Report as need
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/token-lifecycle.md:74
**Known downstream enforcement:** PR #92616 added `is_member_disabled_from_limit()` checks via the organization permission base class. This is **centralized enforcement** — the check runs for every or
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 42a3375c14f5full audit observations/trust-audit/skill/getsentry__sentry-security.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-2942a3375c14f5CAUTIONB89first audit
05

Questions

What does the Sentry Security skill do?

Developer-first error tracking and performance monitoring

Is Sentry Security safe to install?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Sentry Security access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (42a3375c14f5), read on 2026-09-29. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement