analytics-posthog
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides strong security instructions that explicitly forbid the agent from printing or hardcoding sensitive credentials, tokens, or environment variables in chat logs or source files.
- [DATA_EXFILTRATION]: The skill facilitates access to the user's local
~/.build-host/credentials.jsonfile. This access is limited to the skill's primary function of authenticating with the build.host API, and the documentation includes specific safety rules to prevent this sensitive information from being exposed. - [COMMAND_EXECUTION]: The operating procedure involves standard development tasks such as editing project files and interacting with the build.host API to manage environment variables and trigger deployments.
- [SAFE]: The skill does not contain any obfuscated code, remote scripts, or instructions designed to bypass agent safety guidelines.
Audit Metadata