implementing-mcp-tools

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents shell commands for scaffolding YAML configurations and building OpenAPI schemas (e.g., pnpm --filter=@posthog/mcp run scaffold-yaml, hogli build:openapi). These are internal development workflows within the PostHog environment and do not pose a security risk in this context.\n- [SAFE]: The skill emphasizes security best practices, such as requiring a team_id column in HogQL system tables for data isolation. It also references internal project paths and resources (e.g., posthog/api/alert.py, posthog/hogql/database/schema/system.py) which are consistent with the vendor's own codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 06:17 PM
Security Audit — agent-trust-hub — implementing-mcp-tools