query-clickhouse-via-metabase

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the hogli CLI tool to interact with internal databases. This is a legitimate use of command-line tools for a developer-oriented skill.
  • [DATA_EXPOSURE]: Mentions the storage of authentication cookies in ~/.config/posthog/metabase/. The skill explicitly instructs agents to use methods that keep these session values internal to the tool, preventing them from appearing in the agent's transcript.
  • [EXTERNAL_DOWNLOADS]: The skill references internal PostHog infrastructure (metabase.prod-us.posthog.dev and metabase.prod-eu.posthog.dev). These are official domains associated with the skill's author.
  • [DYNAMIC_EXECUTION]: Provides a Python one-liner template for formatting JSON data. This is a low-risk script generation pattern used for data transformation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 06:17 PM
Security Audit — agent-trust-hub — query-clickhouse-via-metabase