posthog-upgrade-migration

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is legitimate, but its trust story is internally inconsistent: it presents a PostHog SDK migration flow while the install target and release-note source do not clearly map to an official PostHog-owned package/repo. This is not confirmed malware, but it is a medium-risk supply-chain concern for an AI agent skill that changes dependencies automatically.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fposthog-upgrade-migration%2F@9f14e15b84ef4d0b5b0a28c87693031c3cb7e401