OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn5 providerslatest audit May 16, 2026
Independent checks from skills.sh's audit partners.
The skill is generally safe and designed to automate Sentry's pull request workflow using the GitHub CLI. It includes privacy-conscious instructions to avoid leaking sensitive data. A low-risk surface for indirect prompt injection exists, as the skill processes untrusted commit messages and existing PR descriptions which could be used to manipulate the agent's behavior or attempt command injection through shell heredoc escaping.
Detected behaviors
No alerts
1 issue
1/1 file flagged
Score: 93/100 · 2 sections analyzed