signals-scout-insight-alerts

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for the PostHog platform and uses specific, pre-authorized MCP tools such as alerts-list, alert-get, and scout-emit-report. All operations remain within the defined analytics and reporting scope.
  • [SAFE]: Data processing is focused on alert metadata (timestamps, values, notification status) and insight configurations. There are no patterns suggesting unauthorized access to sensitive system files or environment variables.
  • [SAFE]: Persistence is implemented correctly using the platform's provided scout-scratchpad tools, which allow the agent to track state (baselines, deduplication) between daily runs without modifying system startup files or shell configurations.
  • [SAFE]: While the skill ingests external data (user-configured alerts and insights), the risk of indirect prompt injection is mitigated by the highly structured nature of the triage instructions and the lack of dangerous capabilities like arbitrary code execution or outbound network requests to untrusted domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 12:28 PM
Security Audit — agent-trust-hub — signals-scout-insight-alerts