llm-analytics-setup

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation and configuration guide for a well-known analytics service (PostHog). It does not contain executable code itself, only snippets for user implementation.\n- [EXTERNAL_DOWNLOADS]: The instructions refer to standard package installations (pip, npm) for official SDKs and reputable open-source frameworks from public registries. These are documented neutrally and are necessary for the skill's stated purpose of instrumentation.\n- [CREDENTIALS_UNSAFE]: All code examples utilize identifiable placeholders (e.g., <ph_project_token>, sk-ant-api..., your_openai_api_key) rather than hardcoded secrets. The skill includes a high-level principle to 'Always use environment variables for PostHog and LLM provider keys. Never hardcode them.'\n- [DATA_EXFILTRATION]: Network operations described in the documentation, such as cURL commands to us.i.posthog.com, are consistent with the primary purpose of sending analytics data to a well-known, trusted service. The skill further provides explicit guidance to 'NEVER send PII in capture() event properties'.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 07:13 AM