signals-scout-product-analytics

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a legitimate product analytics monitoring tool. It uses authorized PostHog tools (MCP) within its designated environment to analyze conversion funnels, retention, and behavioral metrics. All referenced tools and behaviors align with the developer's stated purpose and the PostHog platform's standards.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data including database query results and existing report metadata, which represents a potential injection surface. The implementation mitigates risk by focusing on structured behavioral metrics and requiring validation of denominators (entrant volume) before reporting findings.
  • Ingestion points: SKILL.md (via execute-sql, insight-get, and inbox-reports-list tool outputs)
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: emit_report, edit_report, and execute-sql (read-only).
  • Sanitization: The skill implements logical validation by checking rates against seasonality-matched baselines and entrant volumes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:33 PM
Security Audit — agent-trust-hub — signals-scout-product-analytics