Back to skill

Security audit

PostHog

Security checks for vulnerabilities and agentic risk

Overview

This PostHog skill mostly matches its stated purpose, but it uses powerful API keys with broad read/write access and lacks strong guardrails around host destinations and destructive actions.

Review this skill before installing. Use narrowly scoped PostHog API keys, verify POSTHOG_HOST and POSTHOG_INGEST_HOST point only to official HTTPS PostHog domains or a trusted self-hosted instance, and be careful with HogQL queries and delete/update commands because they can expose or change production analytics data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/posthog.sh:14
Finding

Unvalidated API Host Configuration Can Expose PostHog Credentials

Content
View full analysis
[propertiesJson]" >&2; exit 1; } props="${3:-{}}" curl -sf -H "$CT" -X POST -d "{\"api_key\":\"$PROJECT_KEY\",\"event\":\"$1\",\"distinct_id\":\"$2\",\"properties\":$props}" "$INGEST/i/v0/e/" ;; ``` ```bash evaluate-flags) _project_key_check [[ -z "${1:-}" ]] && { echo "Usage: posthog.sh evaluate-flags [groupsJson]" >&2; exit 1; } groups="${2:-{}}" curl -sf -H "$CT" -X POST -d "{\"api_key\":\"$PROJECT_KEY\",\"distinct_id\":\"$1\",\"groups\":$groups}" "$INGEST/flags?v=2" ;; ``` ```bash whoami) _auth_check _get "$HOST/api/users/@me/" ;; ``` ### Technical Analysis The script accepts `POSTHOG_HOST` and `POSTHOG_INGEST_HOST` directly from environment variables without validating their schemes or destinations. Private API helper functions unconditionally add the personal API key as an `Authorization: Bearer` header. Consequently, setting `POSTHOG_HOST` to an attacker-controlled server causes commands such as `whoami`, `query`, or resource-listing operations to transmit the personal API key to that server. Public ingestion commands place `POSTHOG_PROJECT_API_KEY` directly in JSON request bodies sent to `POSTHOG_INGEST_HOST`. An attacker-controlled ingest host ...[truncated 2733 chars]
Remediation
View remediation
&2 exit 1 ;; esac } _validate_https_host "$HOST" _validate_https_host "$INGEST" ``` For self-hosted installations, replace the fixed allowlist with a carefully validated administrator-controlled allowlis ...[truncated 64 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs use of shell commands (bash scripts/posthog.sh, curl) but does not declare any permissions or allowed-tools scope. That mismatch weakens least-privilege controls and can cause an agent runtime to permit broader shell/network access than reviewers expect, especially because the shell commands operate on live API credentials and remote endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

Events API (deprecated)

The /api/projects/:project_id/events/ endpoint is deprecated. Use HogQL queries or batch exports instead.

Direct curl

bash
# Private endpoint

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes private endpoints that can list persons, query persons, access session recordings, modify records, and delete people, flags, insights, dashboards, experiments, surveys, actions, and recordings. Under the markdown-specific SQP-2 criteria, the description omits explicit warnings that these operations can affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/posthog.sh (reported line 61)May include surrounding context.

sh
_project_key_check
    [[ -z "${2:-}" ]] && { echo "Usage: posthog.sh capture <event> <distinct_id> [propertiesJson]" >&2; exit 1; }
    props="${3:-{}}"
    curl -sf -H "$CT" -X POST -d "{\"api_key\":\"$PROJECT_KEY\",\"event\":\"$1\",\"distinct_id\":\"$2\",\"properties\":$props}" "$INGEST/i/v0/e/"
    ;;

  batch)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/posthog.sh (reported line 68)May include surrounding context.

sh
_project_key_check
    # Reads JSON body from stdin (must include batch array)
    echo "Wrapping with api_key..." >&2
    jq --arg key "$PROJECT_KEY" '. + {api_key: $key}' | curl -sf -H "$CT" -X POST -d @- "$INGEST/batch/"
    ;;

  # ── Public: Feature Flags ──

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The delete-flag command performs a DELETE request against the PostHog API, which can remove a feature flag, but this branch provides no confirmation prompt and no explicit warning that the action is destructive. The surrounding help text lists the command tersely as 'Delete flag' without cautioning about irreversible changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.