posthog-automation
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose is coherent, but its data flow is routed through a third-party MCP/Composio layer rather than official PostHog APIs, and the setup claims are looser than the vendor's documented MCP auth/scoping model. This looks more like an intermediary integration skill than a direct PostHog automation skill, creating medium risk from delegated credentials and remote tool trust rather than confirmed malware.
Confidence: 84%Severity: 64%
Audit Metadata