security-review (Sentry)

Hunts only for exploitable security holes — injection, XSS, broken auth, weak crypto — and deliberately stays quiet unless it can point at attacker-controlled input reaching a vulnerable pattern. It reports high-confidence findings only, so a clean run is not proof of safety.

A situation it fits

Ship is Friday. You want to know whether anything in this quarter of work is genuinely exploitable, and you do not want to wade through naming opinions to find out.
security-review (Sentry). This is the only one that hunts exclusively for exploitable holes and stays quiet otherwise — it reports a finding when it can trace attacker-controlled input to a vulnerable pattern. The broad reviewers all include security, but they hand it to you mixed in with the style nits you just said you did not want.

2 scenarios in the bank answer to security-review (Sentry). The rest are in the game.

Skills it gets confused with

These share a family with security-review (Sentry), which is another way of saying they are the ones you might reach for by mistake.

Knowing what security-review (Sentry) does is the easy half. Telling it apart from the others under time pressure is the game.

Today's session

security-review (Sentry) is part of getsentry/skills. Licence: Apache-2.0. The description above was written for this game, not taken from the skill.

← All skills