integration-javascript_node

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the analysis of 10-15 project files to identify business-critical events for tracking. This creates a surface for indirect prompt injection where untrusted content in the codebase could influence the agent's integration plan. \n
  • Ingestion points: Project source code files (references/basic-integration-1.0-begin.md). \n
  • Capability inventory: The skill utilizes file read/write operations and PostHog MCP tools for dashboard creation. \n
  • Boundary markers: The instructions do not define specific boundary markers for the ingested code content. \n
  • Sanitization: No explicit sanitization logic is prescribed for data extracted from project files before it is used in code generation or dashboard configuration.\n- [EXTERNAL_DOWNLOADS]: The documentation references standard installation procedures for official PostHog SDKs (posthog-node and @posthog/ai) from established package registries. These resources are provided by the verified vendor and align with the skill's intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 09:24 AM
Security Audit — agent-trust-hub — integration-javascript_node