posthog-automation
Warn
Audited by Socket on Jun 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is purpose-aligned for PostHog automation and does not contain obvious malware patterns or local credential theft. The main concern is data-flow integrity: all access is brokered through the Rube/Composio intermediary, which stores auth and executes tools on the user’s behalf, and the referenced Rube service appears discontinued. This is more a third-party trust and credential-forwarding risk than confirmed malicious behavior.
Confidence: 84%Severity: 58%
Audit Metadata