find-bugs

por sentry

Revisão abrangente de código identificando bugs, vulnerabilidades de segurança e problemas de qualidade em alterações de branch. Executa um processo de revisão estruturado em cinco fases: coleta do diff completo, mapeamento de superfícies de ataque, execução de uma checklist de segurança detalhada, verificação de descobertas e auditoria de cobertura antes das conclusões. A checklist de segurança abrange 11 áreas críticas, incluindo injeção, XSS, autenticação, autorização, CSRF, condições de corrida, gerenciamento de sessão, criptografia, divulgação de informações,...

npx skills add https://github.com/getsentry/skills --skill find-bugs

Find Bugs

Review changes on this branch for bugs, security vulnerabilities, and code quality issues.

Phase 1: Complete Input Gathering

  1. Get the FULL diff: git diff $(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')...HEAD
  2. If output is truncated, read each changed file individually until you have seen every changed line
  3. List all files modified in this branch before proceeding

Phase 2: Attack Surface Mapping

For each changed file, identify and list:

  • All user inputs (request params, headers, body, URL components)
  • All database queries
  • All authentication/authorization checks
  • All session/state operations
  • All external calls
  • All cryptographic operations

Phase 3: Security Checklist (check EVERY item for EVERY file)

  • Injection: SQL, command, template, header injection
  • XSS: All outputs in templates properly escaped?
  • Authentication: Auth checks on all protected operations?
  • Authorization/IDOR: Access control verified, not just auth?
  • CSRF: State-changing operations protected?
  • Race conditions: TOCTOU in any read-then-write patterns?
  • Session: Fixation, expiration, secure flags?
  • Cryptography: Secure random, proper algorithms, no secrets in logs?
  • Information disclosure: Error messages, logs, timing attacks?
  • DoS: Unbounded operations, missing rate limits, resource exhaustion?
  • Business logic: Edge cases, state machine violations, numeric overflow?

Phase 4: Verification

For each potential issue:

  • Check if it's already handled elsewhere in the changed code
  • Search for existing tests covering the scenario
  • Read surrounding context to verify the issue is real

Phase 5: Pre-Conclusion Audit

Before finalizing, you MUST:

  1. List every file you reviewed and confirm you read it completely
  2. List every checklist item and note whether you found issues or confirmed it's clean
  3. List any areas you could NOT fully verify and why
  4. Only then provide your final findings

Output Format

Prioritize: security vulnerabilities > bugs > code quality

Skip: stylistic/formatting issues

For each issue:

  • File:Line - Brief description
  • Severity: Critical/High/Medium/Low
  • Problem: What's wrong
  • Evidence: Why this is real (not already fixed, no existing test, etc.)
  • Fix: Concrete suggestion
  • References: OWASP, RFCs, or other standards if applicable

If you find nothing significant, say so - don't invent issues.

Do not make changes - just report findings. I'll decide what to address.

Mais skills de sentry

generate-frontend-forms
sentry
Guia para criar formulários usando o novo sistema de formulários do Sentry. Use ao implementar formulários, campos de formulário, validação ou funcionalidade de salvamento automático.
official
sentry-snapshots-cocoa
sentry
Configuração completa de Snapshots do Sentry para projetos Apple/Cocoa. Use quando for solicitado a "configurar SnapshotPreviews", "configurar testes de snapshot Apple", "enviar snapshots Apple para…
official
architecture-review
sentry
Revisão de saúde do código em nível de equipe. Encontra módulos monolíticos, falhas silenciosas, lacunas de segurança de tipo, buracos na cobertura de testes e problemas de compatibilidade com LLM.
official
linear-type-labeler
sentry
Classifica issues do Linear e aplica um rótulo de Tipo da taxonomia de rótulos do workspace do Sentry com base no conteúdo do título e da descrição de cada issue.
official
sentry-flutter-sdk
sentry
Configuração completa do SDK Sentry para Flutter e Dart. Use quando for solicitado "adicionar Sentry ao Flutter", "instalar sentry_flutter", "configurar Sentry no Dart" ou configurar erro…
official
sentry-svelte-sdk
sentry
Configuração completa do SDK do Sentry para Svelte e SvelteKit. Use quando for solicitado a "adicionar Sentry ao Svelte", "adicionar Sentry ao SvelteKit", "instalar @sentry/sveltekit" ou configurar…
official
vercel-react-best-practices
sentry
Diretrizes de otimização de desempenho para React e Next.js da Vercel Engineering. Esta habilidade deve ser usada ao escrever, revisar ou refatorar React/Next.js…
official
sentry-tanstack-start-sdk
sentry
Configuração completa do SDK Sentry para TanStack Start React. Use quando for solicitado "adicionar Sentry ao TanStack Start", "instalar @sentry/tanstackstart-react" ou configurar erro…
official