instrument-integration
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill utilizes secure practices for secret management, specifically recommending the use of environment variables and providing an MCP tool (projects-get) to retrieve project tokens rather than hardcoding them.
- [SAFE]: All external resources and dependencies originate from the verified vendor (PostHog) or official package registries, which are well-known and trusted sources.
- [SAFE]: The skill performs legitimate software development tasks, such as codebase analysis for framework detection and automated SDK configuration, without using obfuscation or unauthorized data access methods.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface through local codebase analysis and web search results (SKILL.md). It also has shell execution and file-write capabilities. While boundary markers or explicit sanitization are not defined for the ingested data, risks are mitigated by the specific development context and the intended primary purpose of the tool.
Audit Metadata