SKILL ISSUE

Security Review (Sentry) vs Security Review (waybarrios)

Two different Claude skills are both called Security Review. Security Review (Sentry) and Security Review (waybarrios) install under the same name and do different jobs, which is exactly how the wrong one ends up running.

Security Review

Sentry

Hunts only for exploitable security holes — injection, XSS, broken auth, weak crypto — and deliberately stays quiet unless it can point at attacker-controlled input reaching a vulnerable pattern. It reports high-confidence findings only, so a clean run is not proof of safety.

2 scenarios in the bank answer to it

Security Review

waybarrios/opencode-power-pack

Inspects the unmerged commits on a branch and calls out concrete security problems that show realistic exploitation paths, so reviewers can decide whether changes are safe to merge. Unlike broader security-audit or SAST-style tools, it intentionally skips stylistic, architecture, dependency-wide, or general code-review concerns and concentrates only on high-confidence, actionable vulnerabilities in the pending diff.

2 scenarios in the bank answer to it

What is the difference between Security Review (Sentry) and Security Review (waybarrios)?

Security Review (Sentry)
Hunts only for exploitable security holes — injection, XSS, broken auth, weak crypto — and deliberately stays quiet unless it can point at attacker-controlled input reaching a vulnerable pattern. It reports high-confidence findings only, so a clean run is not proof of safety.
Security Review (waybarrios)
Inspects the unmerged commits on a branch and calls out concrete security problems that show realistic exploitation paths, so reviewers can decide whether changes are safe to merge. Unlike broader security-audit or SAST-style tools, it intentionally skips stylistic, architecture, dependency-wide, or general code-review concerns and concentrates only on high-confidence, actionable vulnerabilities in the pending diff.

Should I use Security Review (Sentry) or Security Review (waybarrios)?

The clearest answer is a situation each one is unambiguously right for. Both of these are drawn from the game's question bank.

Reach for Security Review (Sentry) when

Ship is Friday. You want to know whether anything in this quarter of work is genuinely exploitable, and you do not want to wade through naming opinions to find out.

This is the only one that hunts exclusively for exploitable holes and stays quiet otherwise — it reports a finding when it can trace attacker-controlled input to a vulnerable pattern. The broad reviewers all include security, but they hand it to you mixed in with the style nits you just said you did not want.

Reach for Security Review (waybarrios) when

There is a pull request waiting and the release is in an hour. I do not want a report about the whole repo — just tell me whether anything in THESE changes is actually exploitable.

All four are security reviewers, so the question is scope. waybarrios reads only the unmerged commits on the branch and reports concrete exploitation paths, which is precisely a pre-merge decision. Sentry's scans project source and jeffallan produces a prioritised whole-system audit — both answer a bigger question than the one asked, and both cost more than an hour. affaan-m is design-time guidance for code you have not written yet, which is the wrong direction entirely once the PR exists.

What they have in common

Both are filed under Security, the axis along which they collide. That shared ground is what makes an agent pick between them on description alone — and what makes it pick wrong.

Nearby comparisons

Reading the difference is not the same as spotting it at speed. That is the game.

Today's session