posthog-seo-geo-tracking
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of untrusted web-based acquisition data, creating a potential attack surface for indirect prompt injection.\n
- Ingestion points: Untrusted data enters the agent context through referring domains (first_touch_referring_domain), referrer URLs, and UTM parameters extracted from site traffic.\n
- Boundary markers: The skill includes instructions to exclude PII, secrets, and sensitive query-string values from captured events, although it lacks explicit delimiters for the ingested strings themselves.\n
- Capability inventory: The agent is instructed to generate code for implementation and interact with the PostHog API/MCP, providing paths for data exfiltration or system modification if the ingested data successfully influences agent logic.\n
- Sanitization: Implementation instructions require channel normalization and identity stitching logic that includes resetting on logout and verifying billing webhooks.
Audit Metadata