implementing-mcp-tools
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill documents shell commands for scaffolding YAML configurations and building OpenAPI schemas (e.g.,
pnpm --filter=@posthog/mcp run scaffold-yaml,hogli build:openapi). These are internal development workflows within the PostHog environment and do not pose a security risk in this context.\n- [SAFE]: The skill emphasizes security best practices, such as requiring ateam_idcolumn in HogQL system tables for data isolation. It also references internal project paths and resources (e.g.,posthog/api/alert.py,posthog/hogql/database/schema/system.py) which are consistent with the vendor's own codebase.
Audit Metadata