CtrlK
BlogDocsLog inGet started
Tessl Logo

sentry-security

Sentry-specific security review based on real vulnerability history. Use when reviewing Sentry endpoints, serializers, or views for security issues. Trigger keywords: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint".

76

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary procedure-style skill body: concrete vulnerability patterns drawn from real patch history, a classification-to-reference routing table with all referenced files verified to exist, and validation gates (confidence tiers, confirm-absent-from-all-layers, explicit zero-findings instruction) that prevent both false positives and fabricated findings. The only flaw is minor duplication between the Step 3 enforcement-chain checklist and enforcement-layers.md.

DimensionReasoningScore

Conciseness

The body is dense and functional — the IDOR section quotes exact patterns like "Model.objects.get(id=request.data['something_id'])" and "Query includes organization_id=organization.id", with no OWASP-style teaching of concepts Claude already knows. It sits at anchor 4 rather than 5 because of minor trimmable redundancy: the 7-layer chain in Step 3 ("Authentication class → ... → Serializer") substantially duplicates the request-lifecycle list in enforcement-layers.md, and 'a check at any layer counts as enforcement' is stated twice in the body.

4 / 5

Actionability

Every check gives concrete executable guidance: exact red-flag query patterns, exact safe patterns ("Uses self.get_projects() which scopes by org internally"), a 3-question IDOR trace flow, and a fully specified report template with code fences. This matches the top anchor — copy-paste-ready patterns covering the common cases. Not 4 because there are no meaningful gaps between instruction and what to actually execute.

5 / 5

Workflow Clarity

The 4-step sequence (Classify → Check top-6 → Trace full enforcement chain → Report) has explicit validation checkpoints and feedback loops: the confidence table gating what gets reported ("Traced the flow, confirmed no check exists → Report with fix"), "If you cannot confirm the check is absent from every layer, mark the finding as MEDIUM, not HIGH", and "If no checks produced a potential finding, stop and report zero findings." This matches the top anchor — clear sequence with explicit validation steps and error-recovery guidance.

5 / 5

Progressive Disclosure

The body acts as a clean operational overview: a classification table routes each code type to a specific reference file (all six cited files — endpoint-patterns.md, serializer-patterns.md, output-sanitization.md, token-lifecycle.md, privilege-escalation.md, enforcement-layers.md — exist in references/ and are one level deep with no further nesting), plus an explicit "Always load enforcement-layers.md" instruction. Detail is appropriately split, references are clearly signaled by exact path, and navigation is trivial. This matches the top anchor; the minor Step-3/reference duplication is scored under conciseness, not structure.

5 / 5

Total

19

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that answers both what and when explicitly, with an unusually good explicit trigger keyword list that captures natural user phrasings and Sentry-specific vocabulary. The only soft spot is that the capability statement relies on a single action verb applied to several targets rather than enumerating several distinct actions.

DimensionReasoningScore

Specificity

Quotes: "security review based on real vulnerability history", "reviewing Sentry endpoints, serializers, or views for security issues". The description names one core action (security review) applied to several concrete targets (endpoints, serializers, views), placing it between anchor 3 ("1-2 concrete actions") and anchor 4 ("several specific actions"). It is noticeably above the midpoint — the named review targets are specific — but it does not enumerate the distinct sub-actions (e.g., IDOR tracing, token-lifecycle checks) that a top anchor would list.

4 / 5

Completeness

Quotes: "Sentry-specific security review based on real vulnerability history" (what) and "Use when reviewing Sentry endpoints, serializers, or views for security issues" plus an explicit trigger keyword list (when). Both what and when are clearly and explicitly stated with concrete trigger phrases, matching the top anchor's structure. Not 4 because the 'when' clause is fully explicit, not merely present.

5 / 5

Trigger Term Quality

Quotes: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint". This matches the top anchor — comprehensive natural terms including synonyms (IDOR/access control/org scoping/cross-org all capture the same class the way real users would phrase it). Not 4 because few natural variants are missing: a user requesting this work would plausibly say nearly every listed phrase.

5 / 5

Distinctiveness Conflict Risk

Quotes: "Sentry-specific", "reviewing Sentry endpoints, serializers, or views". The description carves a clear niche (Sentry codebase security) with triggers that name the product and its specific vulnerability vocabulary, minimizing conflict risk with generic security-review skills. Not 4 because the Sentry scoping is unambiguous throughout — no broad phrase that another skill could claim.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
getsentry/sentry
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.