review-hog-authoring

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for the agent to act as a developer assistant for the PostHog Review system. It guides the agent in using platform-specific Model Context Protocol (MCP) tools such as posthog:skill-create, posthog:skill-update, skill-list, and skill-get to manage other agent extensions.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it takes user input via interviews to generate new skill instructions. While this is the primary purpose of the skill, it relies on the review agent's downstream safety filters to handle potentially malicious instructions drafted by a user.
  • Ingestion points: User input gathered during the interview phase (Step 2) is used to draft the body of new skills (Step 3).
  • Boundary markers: The instructions do not explicitly mandate delimiters or negative constraints for the generated skill bodies.
  • Capability inventory: The agent uses posthog:skill-create and posthog:skill-update to commit the generated instructions to the platform database.
  • Sanitization: No explicit sanitization of user-provided directions is described in the authoring workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 07:59 AM
Security Audit — agent-trust-hub — review-hog-authoring