exploring-mcp-tool-quality

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions are focused on legitimate data analysis workflows using the PostHog platform tools and event schema.
  • [COMMAND_EXECUTION]: The skill provides SQL query templates for the posthog:execute-sql tool. These queries are designed for data aggregation (calculating percentages and quantiles) on the events table and do not involve arbitrary command execution or system-level access.
  • [DATA_EXFILTRATION]: Network activity and external references are limited to the vendor's official domain (app.posthog.com) and local skill references. The skill retrieves analytics data for reporting purposes within the user's authorized environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies workflows for reading tool execution data, such as $mcp_error_message. While this data originates from external tool calls and could theoretically contain adversarial content, the skill uses it solely for statistical aggregation and structured reporting. No unsafe interpolation or command injection patterns were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 04:00 PM
Security Audit — agent-trust-hub — exploring-mcp-tool-quality