posthog-automation

Warn

Audited by Socket on Jun 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is purpose-aligned for PostHog automation and does not contain obvious malware patterns or local credential theft. The main concern is data-flow integrity: all access is brokered through the Rube/Composio intermediary, which stores auth and executes tools on the user’s behalf, and the referenced Rube service appears discontinued. This is more a third-party trust and credential-forwarding risk than confirmed malicious behavior.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jun 26, 2026, 07:24 PM
Package URL
pkg:socket/skills-sh/rootcastleco%2Frei-skills%2Fposthog-automation%2F@c4c845297d7295fc27fb47d72e02a5df2333327ceaeb74c5520a73a51e05d7b6
Security Audit — socket — posthog-automation