signals-scout-ai-observability

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill is a standard analytical scout for the PostHog platform.
  • [SAFE]: The skill uses a set of dedicated PostHog MCP tools (e.g., query-llm-traces-list, execute-sql, signals-scout-emit-signal) to perform read-only analytics and record findings within the platform's internal scratchpad and inbox.
  • [SAFE]: All external references (such as the deep-dive skills exploring-llm-costs) are part of the authorized vendor's own toolkit within the sandbox environment.
  • [SAFE]: While the skill processes trace data (an ingestion point for potentially untrusted text), its capabilities are strictly limited to monitoring and reporting trends. It does not possess any dangerous capabilities like arbitrary shell execution or external network exfiltration that could be exploited via indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 12:35 PM
Security Audit — agent-trust-hub — signals-scout-ai-observability