exploring-mcp-tool-usage

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data such as tool names, agent intents, and analytics events. While this data could theoretically contain malicious instructions, the skill uses structured, typed tools (e.g., posthog:query-mcp-tool-stats) and server-side resolution for tool names, which limits the potential for prompt injection via data inputs.
  • [COMMAND_EXECUTION]: The skill highlights the use of posthog:execute-sql for cases where pre-defined tools are insufficient. This allows for arbitrary HogQL/SQL execution against the analytics database, which is a standard and documented platform capability for the vendor's data analysis purposes.
  • [DATA_EXPOSURE]: The tools described provide access to analytics data, including person-identifiable information such as emails and names (e.g., in posthog:query-mcp-tool-top-users). This behavior is consistent with the skill's primary purpose as a product analytics exploration tool and uses official platform-integrated tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 03:59 PM
Security Audit — agent-trust-hub — exploring-mcp-tool-usage