All skills
getsentry avatar

/find-bugs

@24361e7 official
by Sentrygetsentry/skills1k stars
53

Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.

Use this Skill: https://skilld.dev/gh/getsentry/skills/find-bugs

This session only. Nothing lands on disk.

SKILL.md

≈49 tokens always: the name and description. ≈652 when used: this file.

Find Bugs

Review changes on this branch for bugs, security vulnerabilities, and code quality issues.

Phase 1: Complete Input Gathering

  1. Get the FULL diff: git diff $(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')...HEAD
  2. If output is truncated, read each changed file individually until you have seen every changed line
  3. List all files modified in this branch before proceeding

Phase 2: Attack Surface Mapping

For each changed file, identify and list:

  • All user inputs (request params, headers, body, URL components)
  • All database queries
  • All authentication/authorization checks
  • All session/state operations
  • All external calls
  • All cryptographic operations

Phase 3: Security Checklist (check EVERY item for EVERY file)

  • Injection: SQL, command, template, header injection
  • XSS: All outputs in templates properly escaped?
  • Authentication: Auth checks on all protected operations?
  • Authorization/IDOR: Access control verified, not just auth?
  • CSRF: State-changing operations protected?
  • Race conditions: TOCTOU in any read-then-write patterns?
  • Session: Fixation, expiration, secure flags?
  • Cryptography: Secure random, proper algorithms, no secrets in logs?
  • Information disclosure: Error messages, logs, timing attacks?
  • DoS: Unbounded operations, missing rate limits, resource exhaustion?
  • Business logic: Edge cases, state machine violations, numeric overflow?

Phase 4: Verification

For each potential issue:

  • Check if it's already handled elsewhere in the changed code
  • Search for existing tests covering the scenario
  • Read surrounding context to verify the issue is real

Phase 5: Pre-Conclusion Audit

Before finalizing, you MUST:

  1. List every file you reviewed and confirm you read it completely
  2. List every checklist item and note whether you found issues or confirmed it's clean
  3. List any areas you could NOT fully verify and why
  4. Only then provide your final findings

Output Format

Prioritize: security vulnerabilities > bugs > code quality

Skip: stylistic/formatting issues

For each issue:

  • File:Line - Brief description
  • Severity: Critical/High/Medium/Low
  • Problem: What's wrong
  • Evidence: Why this is real (not already fixed, no existing test, etc.)
  • Fix: Concrete suggestion
  • References: OWASP, RFCs, or other standards if applicable

If you find nothing significant, say so - don't invent issues.

Do not make changes - just report findings. I'll decide what to address.

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill is designed for automated security and bug auditing of code changes within a git repository. It utilizes standard developer tools like git and the GitHub CLI (gh) to retrieve and analyze diffs. The analysis process follows established secure code review methodologies.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 24361e7. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 6 months ago

README badge

README badge for getsentry/skills/find-bugs

Analyzes branch changes for bugs, security vulnerabilities, and code quality issues through a structured five-phase review: gathering the full diff, mapping attack surface, checking a security checklist covering injection through business logic, verification, and pre-conclusion audit. Designed for code review workflows on Git branches without making changes.

Generated from the current SKILL.md.

Does this skill review all types of code changes or just specific languages?
The skill applies to any code changes on a branch using a language-agnostic attack surface mapping and security checklist. It does not restrict itself to particular languages or frameworks.
What does this skill actually check for?
It checks for security vulnerabilities (injection, XSS, authentication/authorization flaws, CSRF, race conditions, session issues, cryptography misuse, information disclosure, DoS), logic bugs, and code quality issues—prioritizing security issues over others.
Does this skill make code changes or just report findings?
It only reports findings. The skill will not modify code; you decide whether to address the issues it identifies.
How does this skill gather the code to review?
It uses git diff against the default branch to capture all changes, and reads individual files if the diff output is truncated to ensure every changed line is examined.
Will this skill find all bugs?
No. The skill uses static analysis based on attack surface mapping and a security checklist, so it will identify common vulnerabilities and logic flaws but cannot guarantee complete coverage of all possible issues.

Generated from the current SKILL.md. These answers refresh after source changes.