fix-posthog

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected This skill is coherent and aligned with its stated purpose: it contains step-by-step fixes for common PostHog integration problems and uses expected files, environment variables, and verification steps. There are no direct signs of malware or obfuscation in the provided instructions. The main operational risk is the use of an automated executor (codex exec --full-auto) that will run shell commands and modify files — this is powerful and must be trusted by the operator. Writing API keys to .env files and to deployment environments is necessary for the integration but is a sensitive action and should be performed carefully. Overall, the content appears benign with moderate operational risk due to automated execution of commands and handling of secrets.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Ffix-posthog%2F@55bc1ec2b5776cf528710981db84eef48d23a0da