setting-up-a-custom-rest-source
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses official vendor-provided tools for managing data sources within the PostHog ecosystem, such as the external-data-sources-wizard and data-warehouse-source-setup tools.
- [SAFE]: Instructions explicitly mandate that credentials must not be included in the manifest JSON, instead requiring them to be passed via specific, separate parameters which are handled securely by the backend and redacted from responses.
- [SAFE]: The manifest reference documentation notes the presence of an SSRF guard to prevent the use of internal or private hosts in the base_url configuration, mitigating potential server-side request forgery.
- [SAFE]: The workflow mandates validation and preview steps to ensure configuration correctness and verify data mapping against live rows before resource creation.
Audit Metadata