investigate-metric

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill leverages dedicated PostHog MCP tools (e.g., posthog:query-trends, posthog:execute-sql) to perform data analysis. These tools are used as intended within the platform's ecosystem.
  • [SAFE]: Local Python scripts (compare_to_prior_periods.py and breakdown_attribution.py) perform statistical analysis on JSON-formatted metric data. These scripts use only standard library modules and do not include dangerous functions, remote downloads, or unauthorized network operations.
  • [SAFE]: The instruction to use git log for development context is a standard practice for diagnosing changes related to software deployments and does not involve processing untrusted command arguments.
  • [SAFE]: No signs of prompt injection, obfuscation, or credential exposure were found in the skill's instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:21 AM
Security Audit — agent-trust-hub — investigate-metric