Scanned skills

posthog/ai-plugin instrument-product-analytics

Checked the catalogued skill at instrument-product-analytics.

SkillTrust corpus scan 14 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 98
F Security

F; retained sample includes a high finding · SD-022 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

B Transparency

B set by findings not listed in the stored summary

showing 10 of 98
securityhigh SD-022
SKILL.md
securitymedium SD-008
references/EXAMPLE-android.md
securitymedium SD-008
references/EXAMPLE-android.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
5 suppressed by AI triage
securityhigh SD-007 benign_example
references/EXAMPLE-next-app-router.md

The fetch call targets a local API endpoint, not an external host, so it is not a real threat.

securityhigh SD-007 benign_example
references/EXAMPLE-next-pages-router.md

The fetch call targets an internal relative endpoint '/api/auth/login', not an external host, so it does not represent an outbound network call that could exfiltrate data.

permission_hygienehigh SD-003 benign_example
references/EXAMPLE-react-react-router-7-data.md

The code is part of documentation and simply demonstrates relative imports, not an executable path traversal attack.

permission_hygienehigh SD-003 benign_example
references/angular.md

Relative import of environment config is normal, not a malicious path traversal.

securityhigh SD-022 benign_example
references/dotnet.md

Documentation note, no evidence of malicious DNS tunneling