debug-sentry-monitor — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited debug-sentry-monitor (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Automated Sentry issue triage, root cause analysis, fix, architecture audit, and monitoring enhancement workflow. Works with any project — auto-detects configuration from the codebase. Uses the plugin-sentry-sentry MCP server for all Sentry API operations.
NEVER resolve an issue without a verified fix. Resolving means "this will not happen again." If you cannot prove that, leave it unresolved.
NEVER apply a band-aid fix. Wrapping code in try/catch, adding?.chains, or guarding withArray.isArray()are symptom suppressors. Only use defensive coding after fixing the root cause, to harden against truly unpredictable external input.
Understand the WHY before touching any code.
Research before fixing non-trivial bugs. Usefirecrawl_search+firecrawl_scrapeto find best practices for the specific error pattern before implementing a fix.
Before making any Sentry MCP calls, discover the project's Sentry setup.
First, try to detect from local config files. Search for these (in order):
.sentryclirc — contains [defaults] with org and projectsentry.properties — contains defaults.org and defaults.project.env, .env.local, .env.production — look for SENTRY_ORG, SENTRY_PROJECT, SENTRY_DSN, SENTRY_AUTH_TOKENsentry.client.config.ts, sentry.client.config.js — Next.js Sentry configsentry.server.config.ts, sentry.server.config.js — Next.js server Sentry confignext.config.js / next.config.mjs — withSentryConfig() wrapperpackage.json — check for @sentry/* packages to detect SDKIf local detection fails, use the MCP to discover:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "find_organizations")Then for the target org:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "find_projects", arguments: {
"organizationSlug": "<ORG_SLUG>",
"regionUrl": "<REGION_URL>"
})Read package.json (or equivalent) to determine:
| Package | Framework |
|---|---|
@sentry/nextjs | Next.js |
@sentry/react | React SPA |
@sentry/vue | Vue.js |
@sentry/svelte | SvelteKit |
@sentry/node | Node.js backend |
@sentry/browser | Vanilla JS |
sentry-sdk (pip) | Python |
sentry_sdk (pip) | Python |
sentry-ruby | Ruby |
@sentry/angular | Angular |
Search for the Sentry initialization and noise filtering:
Grep for: Sentry.init, sentryInit, initSentry
Grep for: ignoreErrors, beforeSend, denyUrls
Grep for: ErrorBoundary, error-boundary, errorBoundary
Grep for: logger, logging, winston, pino
Grep for: web-vitals, webVitals, reportWebVitalsORG_SLUG: [detected or ask user]
PROJECT_SLUG: [detected or ask user]
REGION_URL: [detected or ask user — typically https://us.sentry.io or https://de.sentry.io]
FRAMEWORK: [detected from packages]
PLATFORM: [browser | server | hybrid]
SENTRY_CONFIG: [path to Sentry.init file]
NOISE_FILTER: [path to file with ignoreErrors/beforeSend]
ERROR_BOUNDARY: [path to error boundary component, if any]
LOGGER: [path to logging utility, if any]If any critical values cannot be detected, ask the user.
Run these two MCP calls in parallel:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "search_issues", arguments: {
"organizationSlug": "<ORG_SLUG>",
"projectSlugOrId": "<PROJECT_SLUG>",
"regionUrl": "<REGION_URL>",
"naturalLanguageQuery": "all unresolved issues from the last 7 days",
"limit": 50
})
CallMcpTool(server: "plugin-sentry-sentry", toolName: "search_events", arguments: {
"organizationSlug": "<ORG_SLUG>",
"projectSlug": "<PROJECT_SLUG>",
"regionUrl": "<REGION_URL>",
"naturalLanguageQuery": "count of errors grouped by error type in the last 7 days",
"limit": 50
})Also check for regressions (issues that were resolved but re-opened):
CallMcpTool(server: "plugin-sentry-sentry", toolName: "search_issues", arguments: {
"organizationSlug": "<ORG_SLUG>",
"projectSlugOrId": "<PROJECT_SLUG>",
"regionUrl": "<REGION_URL>",
"naturalLanguageQuery": "regressed issues in the last 14 days",
"limit": 20
})If no issues are found, report "No unresolved issues in the last 7 days" and proceed to the Architecture Audit (Step 8).
For each issue with >1 event or >0 users impacted:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "get_sentry_resource", arguments: {
"organizationSlug": "<ORG_SLUG>",
"resourceType": "issue",
"resourceId": "<ISSUE_ID>"
})Batch up to 4 calls in parallel per round.
For hard-to-diagnose issues, also fetch breadcrumbs:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "get_sentry_resource", arguments: {
"organizationSlug": "<ORG_SLUG>",
"resourceType": "breadcrumbs",
"resourceId": "<ISSUE_ID>"
})And optionally use Seer for AI-assisted root cause analysis:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "analyze_issue_with_seer", arguments: {
"organizationSlug": "<ORG_SLUG>",
"regionUrl": "<REGION_URL>",
"issueId": "<ISSUE_ID>"
})For understanding issue distribution, check tag values:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "get_issue_tag_values", arguments: {
"organizationSlug": "<ORG_SLUG>",
"regionUrl": "<REGION_URL>",
"issueId": "<ISSUE_ID>",
"tagKey": "browser"
})Common tag keys: url, browser, browser.name, os, environment, release, device, user.
Classify each issue into exactly one bucket:
| Bucket | Signals | Action |
|---|---|---|
| Noise | Extension frames, chunk load errors, browser built-in errors, dev-only environment tag, no app frames in stacktrace | Add noise filter, resolve in Sentry |
| Code Bug | TypeError, ReferenceError, unhandled rejection with app frames, missing function/property | Full root cause analysis (Step 4), fix, verify, resolve |
| Data Bug | Unexpected null/undefined from API, malformed response, stale cache, race condition | Trace data flow end-to-end (Step 4), fix at source |
| Performance | Slow DB query, N+1 API calls, large HTTP payload, high LCP/INP | Do NOT resolve — flag for manual follow-up |
| Regression | Previously resolved issue that re-opened | Highest priority — the original fix was incomplete |
| Config Gap | Missing Sentry feature (logging, metrics, feedback, replay), bad sampling | Implement in config files, resolve |
Priority order: Regressions first, then Code Bugs and Data Bugs, then Noise, then Config Gaps. Performance is always deferred.
For any issue classified as Code Bug, Data Bug, or Regression that meets either threshold:
Run Sentry's AI root-cause analysis before manual investigation:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "analyze_issue_with_seer", arguments: {
"organizationSlug": "<ORG_SLUG>",
"issueId": "<ISSUE_ID>"
})Seer provides:
How to use Seer results:
Note: Seer results are cached — subsequent calls for the same issue return instantly. Analysis for new issues takes ~2-5 minutes.
Do NOT skip or shortcut this step.
From the Sentry issue details, extract:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "find_releases", arguments: {
"organizationSlug": "<ORG_SLUG>",
"regionUrl": "<REGION_URL>",
"projectSlug": "<PROJECT_SLUG>"
})If the issue started after a specific release, check what changed in that release:
git log --oneline <previous-release-tag>..<current-release-tag>git log --oneline -20 -- <file> on culprit files.For non-trivial bugs, research the correct fix pattern:
CallMcpTool(server: "user-firecrawl", toolName: "firecrawl_search", arguments: {
"query": "<framework> <error-type> best practice fix <current year>",
"limit": 5,
"sources": [{ "type": "web" }]
})Then scrape the most authoritative result:
CallMcpTool(server: "user-firecrawl", toolName: "firecrawl_scrape", arguments: {
"url": "<best-result-url>",
"formats": ["markdown"],
"onlyMainContent": true
})Before writing any fix, state:
| Anti-Pattern | Why It's Wrong | Do Instead |
|---|---|---|
Adding ?. to suppress TypeError | Hides the null; downstream gets undefined | Fix why the value is null |
| try/catch that swallows | Error still happens, user sees broken state | Fix the error; if unrecoverable, show user-facing message + re-report |
Array.isArray() guard | Checking consumer instead of fixing producer | Fix the producer |
?? [] or ?? {} fallback | Masks data loading issues | Handle loading/error states explicitly |
Filtering in beforeSend | Muting a real bug | Only filter genuinely external noise |
| Resolving without deploying | Error recurs next session | Only resolve after fix is committed |
Before applying the fix:
Read the project's Sentry config file (detected in Step 0c). Locate the ignoreErrors array or beforeSend function.
Universal noise patterns (safe to add to any web project):
// Browser/extension noise
/^Script error/,
"ResizeObserver loop",
"Non-Error promise rejection captured",
/vid_mate_check/,
/_avast_submit/,
// Network noise (external)
"Failed to fetch",
"Load failed",
"net::ERR_",
"AbortError",
"The operation was aborted",
"cancelled",
// Chunk loading (deployment race)
"ChunkLoadError",
"Loading chunk",
"Failed to fetch dynamically imported module",Framework-specific noise (add only if the framework is detected):
React/Next.js:
"Hydration failed",
"server rendered HTML didn't match",
"Minified React error #418",
"Minified React error #423",
"Minified React error #425",HMR/Dev-only:
"Fast Refresh",
"performing full reload",
"Parsing ecmascript source code failed",Service Worker:
"ServiceWorker",
"Failed to register a ServiceWorker",Noise validation: Before classifying something as noise, verify:
Do NOT attempt. Do NOT resolve. Leave unresolved. Note in the summary.
Implement in the relevant config file based on detected framework.
You may only resolve an issue if ALL of the following are true:
?., try/catch, or type guards as the sole fixIf any checkbox fails, leave the issue unresolved and add it to "Requires Manual Follow-Up."
For each verified fix:
CallMcpTool(server: "plugin-sentry-sentry", toolName: "update_issue", arguments: {
"organizationSlug": "<ORG_SLUG>",
"regionUrl": "<REGION_URL>",
"issueId": "<ISSUE_ID>",
"status": "resolved"
})Batch up to 4 calls in parallel. Do NOT resolve performance issues.
After triaging existing issues (or if no issues exist), audit the Sentry setup itself to identify monitoring gaps and architectural shortcomings.
Read the Sentry config file(s) detected in Step 0c. Check each setting:
| Setting | What to Check | Recommendation |
|---|---|---|
dsn | Is it set from env var, not hardcoded? | Use process.env.SENTRY_DSN or equivalent |
environment | Is it dynamic? | Must read from env var, not hardcoded |
release | Is it set? | Required for deploy correlation and regression detection |
tracesSampleRate | Is it > 0? Is it < 1.0 in production? | 0.1-0.3 for production, 1.0 for dev |
replaysSessionSampleRate | Is it configured? | 0.1 for production |
replaysOnErrorSampleRate | Is it configured? | 1.0 (capture all error replays) |
integrations | Are framework-appropriate integrations present? | See framework-specific recommendations below |
beforeSend | Is it filtering too aggressively? | Should only filter genuinely external noise |
ignoreErrors | Are patterns appropriate? | Cross-check against universal noise list |
Framework-specific integration checks:
| Framework | Expected Integrations |
|---|---|
| Next.js | Auto-configured by @sentry/nextjs — check withSentryConfig in next.config |
| React SPA | BrowserTracing, Replay |
| Node.js | Http, Express/Fastify/Koa, Postgres/Prisma |
| Python | DjangoIntegration / FlaskIntegration, SqlalchemyIntegration |
| Vue | BrowserTracing, Replay, Sentry.vueRouterInstrumentation |
Complement: Sentry catches code-thrown errors. Mushi Mushi catches user-felt friction that never triggers an exception — dead buttons, 12-second screens, broken layouts on one device. Install alongside Sentry: npx mushi-mushi.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.