Skip to content

skill: package getsentry/skills into dockyard #478

Description

@JAORMX

Package agent skills from getsentry/skills into the Dockyard registry.

Source

Rationale

Sentry is an Anthropic skills launch partner and maintains a security-oriented dev skills pack. Strong overlap with Dockyard's existing Trail of Bits security skills (security-review, gha-security-review, skill-scanner, find-bugs).

Candidate skills (to curate)

Security / review (strong fit)

  • skills/security-review — OWASP-style vulnerability review with confidence scoring
  • skills/gha-security-review — GitHub Actions pwn-request/injection audits
  • skills/skill-scanner — scans other skills for malicious patterns (meta-security)
  • skills/find-bugs — defect hunting
  • skills/code-review — general code review
  • skills/claude-settings-audit — audits Claude Code settings.json
  • skills/django-access-review — Django authz review

Dev workflow

  • skills/skill-writer, skills/code-simplifier, skills/commit, skills/create-branch, skills/iterate-pr, skills/pr-writer, skills/gh-review-requests, skills/prompt-optimizer, skills/agents-md, skills/doc-coauthoring, skills/django-perf-review

Likely excluded (Sentry-internal / narrow)

  • skills/sred-project-organizer, skills/sred-work-summary, skills/brand-guidelines, skills/blog-writing-guide, skills/typing-exclusion-worker, skills/presentation-creator

Acceptance criteria

  • One spec.yaml per selected skill under skills/<name>/
  • spec.ref pinned to an audited upstream commit SHA
  • task validate-skill passes for each
  • task scan-skill findings triaged; per-skill security.allowed_issues documented with reasons
  • Single PR grouping all selected skills (branch skills/getsentry)

Part of the vendor-by-vendor sweep following #466 (Trail of Bits).

Metadata

Metadata

Assignees

No one assigned

    Labels

    skillsSkill packaging, vendor skill imports

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions