exploring-mcp-tool-quality

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides canonical SQL recipes for execution via the posthog:execute-sql tool. These queries are designed for telemetry analysis, such as calculating error rates and latency percentiles on the PostHog events table.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to official dashboards on app.posthog.com. These links are legitimate resources provided by the vendor (PostHog) for visual data verification.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it instructs the agent to process data from the events table, including $mcp_error_message and $mcp_tool_name, which could contain untrusted content. This ingestion is necessary for the skill's primary analytical purpose and is handled using standard PostHog tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 01:33 PM
Security Audit — agent-trust-hub — exploring-mcp-tool-quality