Scanned skills

posthog/skills instrument-llm-analytics

Checked the catalogued skill at instrument-llm-analytics.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
D AI-triaged 2
D Security

D; retained sample includes a high finding · SD-022 · what this rule accepts as a false positive →

A Permissions

A set by no findings on this axis

B Transparency

B; retained sample includes a medium finding · SD-007 · what this rule accepts as a false positive →

2 findings
securityhigh SD-022
SKILL.md
transparencymedium SD-007
references/manual-capture.md
5 suppressed by AI triage
securityhigh SD-022 benign_example
references/litellm.md

Documentation example showing a DNS lookup; no evidence of dynamic DNS tunneling or data exfiltration.

securityhigh SD-007 benign_example
references/litellm.md

Example curl to localhost used for local proxy testing; not an outbound malicious request.

securityhigh SD-007 benign_example
references/litellm.md

Example curl to localhost for embeddings; purely illustrative and not a real threat.

securityhigh SD-022 benign_example
references/mastra.md

The code configures a PostHog exporter for observability, with no DNS query or dynamic hostname usage, so DNS exfiltration is unlikely.

securityhigh SD-022 benign_example
references/openai-agents.md

The host URL points to a legitimate PostHog API endpoint, not a suspicious DNS tunneling pattern.