Scanned skills

posthog/skills instrument-feature-flags

Checked the catalogued skill at instrument-feature-flags.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 38
D Security

D; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →

F Permissions

F set by findings not listed

B Transparency

B; retained sample includes a medium finding · SD-007 · what this rule accepts as a false positive →

showing 10 of 38
securityhigh SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
transparencymedium SD-007
references/adding-feature-flag-code.md
securityhigh SD-007
references/adding-feature-flag-code.md
3 suppressed by AI triage
securityhigh SD-022 benign_example
SKILL.md

The content merely describes a mapping of regions to host URLs, not executing a DNS lookup.

securityhigh SD-022 benign_example
references/dotnet.md

Documentation note, no evidence of malicious DNS tunneling

permission_hygienehigh SD-003 benign_example
references/next-js.md

Dynamic import of a local JSON file using a relative path is normal and does not read or write outside the project directory.