signals-scout-revenue-analytics
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates using official PostHog MCP tools (e.g.,
execute-sql,emit_report) to monitor internal project analytics and data warehouse health. - [SAFE]: All data access and reporting actions are aligned with the skill's stated purpose of being a revenue analytics watchdog.
- [SAFE]: No evidence of prompt injection, data exfiltration to untrusted domains, or persistence mechanisms was found.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources like
external_data_sourcesandevent_properties. While this constitutes an attack surface, the risk is minimized as the data consists of internal project metadata and the output is directed to human-reviewed inbox reports. No exploitation patterns were observed.
Audit Metadata