posthog-automation

Warn

Audited by Socket on Jun 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated PostHog automation purpose, and there is no local malware-style installer behavior. However, it routes authentication and data through a third-party hosted MCP gateway instead of direct PostHog APIs, and the referenced Rube service has discontinuation/maintenance uncertainty. Risk is driven by intermediary credential/data flow and the ability to make production-affecting analytics and feature-flag changes, not by confirmed malicious content.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Jun 25, 2026, 09:54 AM
Package URL
pkg:socket/skills-sh/sitaurs%2Fpbl-ppe-detection%2Fposthog-automation%2F@b75562a4a4862deebb6d2a394347a21e3301defdefab13aad26f9b27b4b64f55
Security Audit — socket — posthog-automation