querying-posthog-data

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential indirect injection vector through project-authored metrics in the data catalog. It provides explicit security instructions for the agent to treat MarkdownDefinition content as untrusted data rather than commands, instructing the agent to ignore any embedded attempts to call tools or bypass safety constraints. Evidence Chain: Ingestion points include posthog:data-catalog-metric-run (SKILL.md); Boundary markers involve checking metric approval status and drift; Capability inventory includes SQL execution and entity management; Sanitization is enforced via strict instructions to the agent to treat content as non-executable.
  • [SAFE]: The skill demonstrates security awareness by recommending selective property retrieval to avoid data exposure, time-bounding all queries for performance, and warning against echoing sensitive data such as temporary download URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 02:48 PM
Security Audit — agent-trust-hub — querying-posthog-data