exploring-mcp-intent-clusters

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no malicious code, persistence mechanisms, or unauthorized network operations. All tools and URLs (app.posthog.com) are consistent with official PostHog services and functionality.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection (Category 8) because it processes $mcp_intent free-text strings generated by other agents. Ingestion point: Data enters the context via tool call intents described in SKILL.md. Boundary markers: None provided in instructions. Capability inventory: Limited to posthog:mcp-analytics-intent-clusters-retrieve and posthog:mcp-analytics-intent-clusters-recompute. Sanitization: Not specified. The risk is considered SAFE as the tools only perform analytical operations within a controlled platform environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 12:28 PM
Security Audit — agent-trust-hub — exploring-mcp-intent-clusters