NYC

sentry-setup-metrics

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] This skill is consistent with its stated purpose: it documents how to enable and instrument Sentry custom metrics in JS/TS and Python projects. It asks for expected inputs (project manifests, DSN) and recommends legitimate SDK packages and configuration. There are no signs of credential harvesting, obfuscated code, unknown third-party proxies, or malicious behaviors. The primary risk is operational: developers may accidentally include sensitive or high-cardinality attributes in metrics; the skill properly warns about that and gives filtering examples. Overall, the skill appears benign and appropriate for its purpose. LLM verification: This is an instructional skill that documents how to enable and use official Sentry metrics in supported runtimes. There is no evidence of malicious code or obfuscated payloads. Primary security concerns are operational: avoid hardcoding DSNs, do not send PII/secrets as metric attributes (use beforeSendMetric to scrub), and prefer pinned/package-version controls rather than unpinned 'latest' installs to reduce supply-chain risk. The content is safe to follow if practitioners apply standard secur

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:41 AM
Package URL
pkg:socket/skills-sh/getsentry%2Fsentry-for-claude%2Fsentry-setup-metrics%2F@3d65bf707b1cbeeb87412a6d395d63692f3b1cc0