signals-scout-observability-gaps

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or persistence mechanisms were detected. The skill is authored by PostHog and operates within its intended analytics ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted telemetry data, such as event names and insight descriptions, from the database. While this represents a potential surface for indirect prompt injection, the risk is minimized by the skill's specific focus on reporting and its explicit instructions to properly escape SQL literals (quotes, backslashes, and wildcards). This is a standard functional requirement for an observability tool and is handled according to best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:03 AM
Security Audit — agent-trust-hub — signals-scout-observability-gaps