deepsourcecorp/skills · Archived

sentinel-api

Scan code for security vulnerabilities, leaked secrets, and dependency issues using the Sentinel API (sentinel.deepsource.com), and auto-fix detected issues. Use this skill when asked to: (1) Scan or analyze a repository or code for security issues, secrets, or vulnerabilities using Sentinel, (2) Upload/sync a local git repository to Sentinel for analysis, (3) Run Sentinel on code changes, pull requests, or patches, (4) Apply auto-fixes from Sentinel analysis results. Requires a Sentinel API ke…

First seen Apr 21, 2026

Installation

$ npx skills add deepsourcecorp/skills --skill sentinel-api

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from deepsourcecorp/skills.

npx skills add deepsourcecorp/skills

Browse all from deepsourcecorp/skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 3
License LICENSE
Default branch master
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 5,100 B
  • docs SUMMARY.md 561 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 11 installs

SKILL.md

Sentinel API

Scan code for security vulnerabilities, secrets, and dependency issues via the Sentinel REST API, and auto-fix detected issues.

Authentication

All API calls require a Bearer token. Read the key from the SENTINELAPIKEY environment variable:

curl https://sentinel.deepsource.com/api/v1/workspace \
  -H "Authorization: Bearer $SENTINEL_API_KEY"

If the key is not set, ask the user to provide it. Never hardcode API keys or pass them as command-line arguments. All bundled scripts read from this environment variable automatically.

Workflow

Step 1: Create a repository

curl -X POST https://sentinel.deepsource.com/api/v1/repositories \
  -H "Authorization: Bearer $SENTINEL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "my-repo",
    "external_id": "local:my-repo",
    "detection": ["security", "secrets"],
    "fix": ["security", "secrets"]
  }'

Save the returned id (e.g., repo...). Use externalid to avoid duplicates — if a repo with the same external_id exists, retrieve it with GET /repositories/external:local:my-repo instead.

Step 2: Sync code

Use the bundled scripts/sync_repo.sh script:

# Full sync (first time)
./scripts/sync_repo.sh /path/to/repo <repo_id>

# Incremental sync (subsequent updates)
./scripts/sync_repo.sh /path/to/repo <repo_id> <base_ref>

The script creates a git bundle, obtains a signed upload URL, uploads the bundle, and polls until sync completes. It outputs the sync ID on success.

Manual sync steps (if not using the script):

  1. Create a git bundle:

``bash # Full git bundle create repo.bundle --all # Incremental from a base ref git bundle create repo.bundle <base_ref>..HEAD ``

  1. Create a sync: POST /repositories/{id}/syncs with {"type": "full"} or {"type": "incremental", "base_ref": "<ref>"}
  1. Upload the bundle to the upload_url from the response:

``bash curl -X PUT "<upload_url>" -H "Content-Type: application/octet-stream" --data-binary @repo.bundle ``

  1. Poll GET /repositories/{id}/syncs/{sync_id} until status is completed.

Step 3: Run analysis

curl -X POST https://sentinel.deepsource.com/api/v1/analysis \
  -H "Authorization: Bearer $SENTINEL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "repository",
    "repository_id": "<repo_id>",
    "from_ref": "<commit_sha>"
  }'
  • from_ref (required): the git commit/ref to analyze from. Use the full SHA of HEAD for a full scan.
  • to_ref (optional): end ref for analyzing a range of changes.
  • patch (optional): git patch to apply before analysis. Mutually exclusive with to_ref.

Step 4: Poll for results

Use the bundled scripts/poll_analysis.sh script:

RESULT=$(./scripts/poll_analysis.sh <analysis_id>)

Or poll manually: GET /analysis/{id} until status is completed.

Step 5: Inspect results and apply fixes

The completed analysis contains:

  • detection_result.issues — list of detected issues with file, position, explanation, category
  • fix_result.patch — unified diff patch that fixes the detected issues
  • fix_result.fixes — individual fixes with explanations

Apply the fix patch:

echo "$FIX_PATCH" | git apply

If only the first 50 issues/fixes are returned (has_more: true), paginate with:

  • GET /analysis/{id}/issues?limit=100
  • GET /analysis/{id}/fixes?limit=100

Detection Categories

Category Description
security Code vulnerabilities (injection, XSS, unsafe deserialization, etc.)
secrets Leaked credentials, API keys, tokens in source code
dependencies Vulnerable dependencies

Default detection: ["security", "secrets"]. Set per-repository or per-analysis.

Key Patterns

Reuse repositories: Look up existing repos by externalid (GET /repositories/external:<externalid>) before creating new ones.

Incremental syncs: After the first full sync, use incremental syncs with base_ref set to the last synced commit for faster uploads.

Idempotency: Send Idempotency-Key header on create operations for safe retries.

Ref for full scan: To scan the entire repo, set from_ref to the root commit or the HEAD commit SHA after syncing.

API Reference

For detailed endpoint documentation, request/response schemas, pagination, and error codes, see [references/api-reference.md](references/api-reference.md).