posthog-automation
Warn
Audited by Socket on Jun 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities match its stated PostHog automation purpose, and there is no local malware-style installer behavior. However, it routes authentication and data through a third-party hosted MCP gateway instead of direct PostHog APIs, and the referenced Rube service has discontinuation/maintenance uncertainty. Risk is driven by intermediary credential/data flow and the ability to make production-affecting analytics and feature-flag changes, not by confirmed malicious content.
Confidence: 83%Severity: 61%
Audit Metadata