posthog
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto fetch and execute the@useclawlink/clipackage from the npm registry, which is the official tool for this integration. - [DYNAMIC_EXECUTION]: The agent is instructed to use shell commands to interact with PostHog via the ClawLink CLI, including listing resources and running actions.
- [DATA_EXPOSURE]: Authentication is handled via a browser flow, and the resulting credentials are stored in
~/.clawlink/credentials.json, which is consistent with standard CLI security practices.
Audit Metadata