agent-posthog

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent with PostHog analytics work, and its documented data targets look legitimate, but it relies on unverified local binaries that receive a personal API key. That combination makes the skill high risk on install/execution trust even without direct evidence of malicious intent.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Jul 16, 2026, 01:20 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-posthog%2F@d9622aad0dbb4e28af4e97040b9bdead165b3090ddca6d5904d8d1f274fc6422
Security Audit — socket — agent-posthog