Scanned skills

posthog/skills instrument-integration

Checked the catalogued skill at instrument-integration.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 102
F Security

F; retained sample includes a high finding · SD-022 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

B Transparency

B set by findings not listed in the stored summary

showing 10 of 102
securityhigh SD-022
SKILL.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-angular.md
permission_hygienehigh SD-003
references/EXAMPLE-astro-hybrid.md
permission_hygienehigh SD-003
references/EXAMPLE-astro-hybrid.md
11 suppressed by AI triage
securitymedium SD-008 benign_example
references/EXAMPLE-android.md

Documentation example, not malicious usage

securitymedium SD-008 benign_example
references/EXAMPLE-android.md

Documentation example, not malicious usage

securityhigh SD-007 benign_example
references/EXAMPLE-next-app-router.md

The fetch call targets a local API endpoint, not an external host, so it is not a real threat.

securityhigh SD-007 benign_example
references/EXAMPLE-next-pages-router.md

The fetch call targets an internal relative endpoint '/api/auth/login', not an external host, so it does not represent an outbound network call that could exfiltrate data.

permission_hygienehigh SD-003 benign_example
references/EXAMPLE-react-react-router-7-data.md

The code is part of documentation and simply demonstrates relative imports, not an executable path traversal attack.

permission_hygienehigh SD-003 benign_example
references/angular.md

Relative import of environment config is normal, not a malicious path traversal.

securityhigh SD-022 benign_example
references/dotnet.md

Documentation note, no evidence of malicious DNS tunneling

permission_hygienehigh SD-003 benign_example
references/next-js.md

Dynamic import of a local JSON file using a relative path is normal and does not read or write outside the project directory.

securityhigh SD-022 benign_example
references/react-router-v6.md

The snippet instructs adding environment variables; there is no dynamic DNS lookup or tunneling.

securityhigh SD-022 benign_example
references/react-router-v7-data-mode.md

The snippet instructs adding environment variables; there is no dynamic DNS lookup or tunneling.

securityhigh SD-022 benign_example
references/react-router-v7-declarative-mode.md

The snippet instructs adding environment variables; there is no dynamic DNS lookup or tunneling.