agent-posthog
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, and its PostHog-oriented commands are proportionate, but it relies on unverified local CLIs and sends PostHog credentials through them. Because the binary provenance is not established and the tool receives API keys, this is a high security risk even without clear evidence of confirmed malicious exfiltration.
Confidence: 84%Severity: 84%
Audit Metadata