instrument-feature-flags

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured workflow for instrumenting feature flags using official PostHog SDKs across multiple programming languages and frameworks including React, Python, Node.js, and others.- [SAFE]: Sensitive information is handled securely by prioritizing environment variables over hardcoded keys. The skill uses official PostHog domains (e.g., us.i.posthog.com) and provides instructions for retrieving project tokens through authenticated MCP tools or user input.- [SAFE]: The analysis of project source code and configuration files (package.json, .env) is conducted for the legitimate purpose of platform detection and SDK initialization, following standard developer automation practices.- [SAFE]: All external references and dependency recommendations target official PostHog repositories and well-known package registries (NPM, PyPI, Maven Central, etc.).
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 12:26 AM
Security Audit — agent-trust-hub — instrument-feature-flags