agent-posthog

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes agent-posthog and mockposthog CLI tools for data retrieval and project management. These tools are vendor-specific resources associated with the skill author 'shhac' and are used for their intended analytical purposes.
  • [CREDENTIALS_UNSAFE]: Security best practices are emphasized in the documentation. It explicitly instructs the agent never to request personal API keys in plain text and directs users to utilize local OS dialogs (--form flag) for secure authentication setup.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the official PostHog domain (us.posthog.com), which is a well-known service for product analytics. No unauthorized or suspicious external connections were detected.
  • [DATA_EXFILTRATION]: Data operations are confined to the user's authorized PostHog environment. The skill documentation promotes the use of read-only commands and explicit project scoping to prevent accidental data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 01:19 PM
Security Audit — agent-trust-hub — agent-posthog