signals-scout-revenue-analytics

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates using official PostHog MCP tools (e.g., execute-sql, emit_report) to monitor internal project analytics and data warehouse health.
  • [SAFE]: All data access and reporting actions are aligned with the skill's stated purpose of being a revenue analytics watchdog.
  • [SAFE]: No evidence of prompt injection, data exfiltration to untrusted domains, or persistence mechanisms was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources like external_data_sources and event_properties. While this constitutes an attack surface, the risk is minimized as the data consists of internal project metadata and the output is directed to human-reviewed inbox reports. No exploitation patterns were observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:02 AM
Security Audit — agent-trust-hub — signals-scout-revenue-analytics