signals-scout-apm

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates within the PostHog agent environment, using specialized internal tools (apm-* and scout-*) for telemetry analysis and reporting findings to a designated inbox. This is consistent with its stated purpose.
  • [SAFE]: No unauthorized network operations, hardcoded credentials, or access to sensitive local filesystem paths (e.g., .ssh, .aws) were identified.
  • [SAFE]: The use of a scratchpad for 'durable steering' is a legitimate feature of the platform for maintaining state between runs, such as recording baselines and preventing duplicate reports, rather than a malicious persistence mechanism.
  • [SAFE]: No obfuscation, prompt injection, or dynamic code generation from untrusted sources was detected. References to scripts are localized to a bundled sibling skill, following standard architecture for complex agent workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 12:28 PM
Security Audit — agent-trust-hub — signals-scout-apm