Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计通过

sentry-javascript-bugsSentry JavaScript bugs 搜索

Agent Skill

用于辅助 Java 项目开发、面向对象设计、Spring 生态、Maven 或 Gradle 依赖和后端工程实践。它适合让 Agent 分析类结构、设计接口、整理服务分层、生成测试或检查常见代码坏味道。使用时需要结合项目已有架构、包结构和依赖版本,不应只按通用教程改代码;涉及数据库、事务、并发或框架配置时,应先确认运行环境和回归测试范围。

总安装

1,395

周安装

57

GitHub Stars

43,738

下载量

447
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:sentry-javascript-bugs(Sentry JavaScript bugs 搜索)
来源仓库:https://github.com/getsentry/sentry
仓库路径:skills/sentry-javascript-bugs
安装命令:
npx skills add https://github.com/getsentry/sentry --skill sentry-javascript-bugs
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/getsentry/sentry --skill sentry-javascript-bugs

简介

用于辅助 Java 项目开发、Spring 生态和后端工程实践。

  • 适合分析类结构、设计接口或生成测试用例时使用。
  • 通过 GitHub 安装后,结合项目架构调用分析能力。
  • 修改代码前应确认运行环境及回归测试策略。
  • sentry-javascript-bugs 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Sentry JavaScript Frontend Bug Pattern Review

Find bugs in Sentry frontend code by checking for the patterns that cause the most real production errors.

This skill encodes patterns from 428 real production issues (201 resolved, 130 ignored, 97 unresolved) generating over 524,000 error events across 93,000+ affected users. These are not theoretical risks -- they are the actual bugs that ship most often, with known fixes from resolved issues.

Scope

Review the code provided by the user, Warden, or the current branch diff. If the user does not provide a target, review the current branch diff. Start from the changed hunk or file, then read outward only as needed to confirm the behavior.

  1. Analyze the changed code against the pattern checks below.
  2. Use Read and Grep to trace data flow beyond the initial diff when needed. Follow component props, hook return values, API response shapes, and state transitions until the behavior is confirmed.
  3. Report only HIGH and MEDIUM confidence findings.
ConfidenceCriteriaAction
HIGHTraced the code path, confirmed the pattern matches a known bug classReport with fix
MEDIUMPattern is present but context may mitigate itReport as needs verification
LOWTheoretical or mitigated elsewhereDo not report

Step 1: Classify the Code

Determine what you are reviewing and load the relevant reference.

Code TypeLoad Reference
Null/undefined property access, optional chaining, object destructuringreferences/null-reference-errors.md
Dashboard widgets, chart visualization, widget URL generationreferences/dashboard-widget-errors.md
Trace views, span details, trace tree renderingreferences/trace-view-errors.md
API calls, response handling, error states, fetch wrappersreferences/api-response-handling.md
React hooks, context providers, render loops, component lifecyclereferences/react-lifecycle-errors.md
AI Insights, LLM prompt parsing, gen_ai span datareferences/ai-insights-parsing.md
Array operations, date/time values, numeric formattingreferences/range-and-bounds-errors.md

If the code spans multiple categories, load all relevant references.

Step 2: Check for Top Bug Patterns

These are ordered by combined frequency and impact from real production data.

Check 1: Null/Undefined Property Access -- 158 issues, 46,337 events

Code accesses a property on a value that may be null or undefined. This is the single most common bug pattern in the Sentry frontend.

Red flags:

  • Accessing .id, .slug, .name, .type, .match, .length, .charCodeAt without null checks
  • Using object.property instead of object?.property on data from API responses
  • Passing API response data directly to utility functions without null validation
  • Accessing DOM element properties from querySelector or useRef without checking if the element exists
  • Destructuring objects from hooks/stores that may return null during loading states
  • Calling .dispatchEvent() on elements that have been unmounted

Safe patterns:

  • Optional chaining: obj?.property?.nested
  • Default values: const value = obj?.field?? defaultValue
  • Null guards before function calls: if (data) {parser.parse(data);}
  • Early returns for null/undefined parameters in utility functions

Check 2: Dashboard Widget Input Validation -- 6 issues, 90,482 events

Widget visualization components throw when receiving data in unexpected formats.

Red flags:

  • Rendering chart components without checking if data contains plottable values
  • Calling getWidgetExploreUrl() for widget types that do not support multiple queries
  • Passing undefined field values to parseFunction() or similar field parsers
  • Not handling empty API responses in widget data fetchers

Safe patterns:

  • Validate data shape before rendering: if (!hasPlottableValues(data)) return <EmptyState />
  • Check widget query count before generating explore URLs
  • Guard field parsers: if (!field) return null

Check 3: Trace View Data Integrity -- 12 issues, 328,482 events

The trace tree renderer and trace detail views encounter data that violates structural assumptions.

Red flags:

  • Building trace trees without cycle detection (or detecting cycles but not handling them gracefully)
  • Looking up projects by ID from span data without checking if the project is accessible
  • Generating trace links without validating traceSlug is non-empty
  • Using captureException in render paths without deduplication (fires every render cycle)

Safe patterns:

  • Break cycles by detaching cyclic nodes as orphan roots
  • Validate traceSlug before generating links: if (!traceSlug) return fallbackLink
  • Deduplicate error captures using a ref: if (!capturedRef.current) {captureException(...); capturedRef.current = true;}
  • Check project access before rendering span details

Check 4: API Response Shape Assumptions -- 31 issues, 24,019 events

Frontend code assumes API responses have a specific shape but the response is empty, undefined, or has an unexpected status code.

Red flags:

  • Not handling 200 responses with empty bodies (e.g., GET /customers/{orgSlug}/ returns 200 with no body)
  • Not handling 402 (Payment Required) status codes in subscription flows
  • Not handling 409 (Conflict) status codes in mutation endpoints
  • Treating UndefinedResponseBodyError as unexpected (it indicates the API returned no parseable body)
  • Assuming SelectAsync options will always load successfully

Safe patterns:

  • Check response body before parsing: if (!response.body) return null
  • Handle specific 4xx status codes in catch blocks
  • Provide fallback empty states for failed API fetches instead of throwing

Check 5: React Lifecycle Violations -- 10 issues, 2,595 events

Components violate React rendering rules, causing infinite loops or crashes.

Red flags:

  • Setting state unconditionally in useEffect without proper dependency arrays
  • Calling useOrganization() in components that render before organization context is loaded
  • Using useContext() outside the provider boundary
  • Passing objects as React children instead of strings/elements
  • Components that trigger immediate re-render on mount

Safe patterns:

  • Always provide dependency arrays for useEffect
  • Guard context hooks: const org = useOrganization(); if (!org) return <Loading />
  • Wrap organization-dependent routes in a provider boundary
  • Validate element types before rendering: if (typeof Component!== 'function') return null

Check 6: AI Insights Data Parsing -- 2 issues, 3,005 events

JSON parsing of AI prompt messages and gen_ai span data fails on non-standard formats.

Red flags:

  • Calling JSON.parse() on ai.prompt.messages span attributes without try-catch
  • Assuming all AI model responses produce valid JSON
  • Not handling the "parts" format for multi-modal AI messages

Safe patterns:

  • Wrap all JSON.parse calls on external data in try-catch
  • Check for leading [ or { before parsing
  • Provide raw-text fallback rendering when parsing fails

Check 7: Array and Bounds Validation -- 15 issues, 3,120 events

Array operations and numeric formatting with values that exceed valid ranges.

Red flags:

  • Using result.push(...largeArray) (crashes when array is too large)
  • Passing unclamped values to toLocaleString({maximumFractionDigits: n})
  • Constructing Date objects from unvalidated timestamps
  • Recursive component rendering without depth limits

Safe patterns:

  • Use concat or iterative push for potentially large arrays
  • Clamp numeric format parameters: Math.min(100, Math.max(0, precision))
  • Validate dates before constructing: if (isNaN(new Date(ts).getTime())) return fallback
  • Use iterative rendering with explicit stacks for deeply nested structures

Check 8: Logic Correctness -- not pattern-based

After checking all known patterns above, reason about the changed code itself:

  • Does every code path return the correct type (or JSX)?
  • Are all branches of conditionals handled (especially missing else / default cases in switches)?
  • Can any prop or state value (null, undefined, empty array, empty string) cause unexpected behavior?
  • Are hook dependency arrays correct? Missing deps cause stale closures; extra deps cause infinite loops.
  • If this component unmounts mid-async-operation, is cleanup handled?

Only report if you can trace a specific input that triggers the bug. Do not report theoretical concerns.

If no checks produced a potential finding, stop and report zero findings. Do not invent issues to fill the report. An empty result is the correct output when the code has no bugs matching these patterns.

Each code location should be reported once under the most specific matching pattern. Do not flag the same line under multiple checks.

Step 3: Report Findings

For each finding, provide the evidence the review harness needs:

  • precise location
  • severity and confidence
  • concrete triggering input or state
  • root cause and consequence
  • a matching production precedent when available
  • a concrete code fix, preferably as a unified diff when the harness supports it

Fix suggestions must include actual code. Never suggest a comment or docstring as a fix.

Do not prescribe your own output format — the review harness controls the response structure.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

31.8%
按下载量换算142

Claude

28.67%
按下载量换算128

Cursor

20.06%
按下载量换算90

Gemini CLI

10.3%
按下载量换算46

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills