posthog-automation

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates automation for PostHog through the Rube MCP service. All external references and tools are consistent with the primary use case.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from PostHog project events and feature flag configurations, creating a potential indirect prompt injection surface. This ingestion is inherent to the skill's primary purpose of analytics management. * Ingestion points: POSTHOG_LIST_AND_FILTER_PROJECT_EVENTS, POSTHOG_RETRIEVE_FEATURE_FLAG_DETAILS; * Boundary markers: None mentioned in the instructions; * Capability inventory: Tool-based capabilities for event capture and project management; * Sanitization: Not specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 05:34 AM
Security Audit — agent-trust-hub — posthog-automation