signals-scout-feature-flags
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is data analysis and reporting within its intended platform (PostHog).
- [SAFE]: It specifically addresses the risk of indirect prompt injection by identifying event-supplied data (such as flag keys and responses) as untrusted and instructing the agent to sanitize it before inclusion in reports.
- [SAFE]: All operations use authorized platform tools (MCP) for database queries, project metadata retrieval, and report generation.
- [SAFE]: The skill follows the principle of least privilege by focusing on specifically allowed reporting tools and read-only data access for its core functions.
Audit Metadata