Agent skill

Posthog Prod Checklist

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Run a fail-safe production-readiness review for PostHog instrumentation, flags, secrets, privacy, delivery, and rollback.

MITAuto-check: notesDevOps & Cloud

Install Posthog Prod Checklist

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-prod-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace posthog-prod-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/posthog-prod-checklist .claude/skills/posthog-prod-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
posthog-prod-checklist
GitHub stars
2.8k
Token cost
~2.1k tokens
SKILL.md length
415 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Run a fail-safe production-readiness review for PostHog instrumentation, flags, secrets, privacy, delivery, and rollback.

  • Works in 5 steps: Production SDK Configuration → Graceful Degradation → Health Check Endpoint → …
  • Enabling a new production integration
  • SKILL.md covers Overview, Prerequisites, Instructions and Error Handling, plus 5 more sections
  • Calls kubectl, curl and jq; reaches us.i.posthog.com; needs NEXT_PUBLIC_POSTHOG_KEY and POSTHOG_FEATURE_FLAGS_SECURE_API_KEY

What it does

Posthog Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Run a fail-safe production-readiness review for PostHog instrumentation, flags, secrets, privacy, delivery, and rollback. Use when enabling a new production integration or major SDK change. Trigger with "PostHog production checklist", "PostHog go-live", or "review PostHog launch".

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud. It works with PostHog. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Enabling a new production integration
  • Major SDK change
  • With PostHog production checklist
  • PostHog go-live

Example prompts

  • “PostHog production checklist”
  • “PostHog go-live”
  • “review PostHog launch”
  • “/posthog-prod-checklist”

Requirements

  • Node.js
  • A credential in NEXT_PUBLIC_POSTHOG_KEY
  • A credential in POSTHOG_FEATURE_FLAGS_SECURE_API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(kubectl:*), Bash(curl:*), Grep

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Production SDK Configuration
  2. Graceful Degradation
  3. Health Check Endpoint
  4. Serverless Function Pattern
  5. Pre-Flight Verification

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(kubectl:*)
    • Bash(curl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • us.i.posthog.com

    Also links to:

    • posthog.com
    • status.posthog.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NEXT_PUBLIC_POSTHOG_KEY
    • POSTHOG_FEATURE_FLAGS_SECURE_API_KEY
    • POSTHOG_PERSONAL_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Posthog Prod Checklist loads about 2.1k tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 415 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:55
    - [ ] `.env` files in `.gitignore`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 415 words, ~2,101 tokens.

Download SKILL.mdSave it as .claude/skills/posthog-prod-checklist/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
posthog-prod-checklist
description
Run a fail-safe production-readiness review for PostHog instrumentation, flags, secrets, privacy, delivery, and rollback. Use when enabling a new production integration or major SDK change. Trigger with "PostHog production checklist", "PostHog go-live", or "review PostHog launch".
allowed-tools
Read, Bash(kubectl:*), Bash(curl:*), Grep
compatibility
Designed for Claude Code
argument-hint
[project-path] [release-ref]
version
1.14.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, posthog, deployment

PostHog Production Checklist

Overview

Production readiness verification for PostHog integrations. Covers SDK configuration hardening, graceful degradation when PostHog is unavailable, health check endpoints, proper shutdown hooks for serverless, and rollback procedures.

Prerequisites

  • PostHog integration tested in staging
  • Production PostHog project with phc_ key
  • Least-privilege private API credential only for the private operations the integration actually performs
  • Deployment pipeline configured

Instructions

Tool discipline

Use Read to inspect the relevant configuration and implementation before proposing changes. Use Grep to locate initialization, capture, flag, and credential boundaries.

Pre-Deployment Checklist

SDK Configuration:

  • api_host set to correct region (us.i.posthog.com or eu.i.posthog.com)
  • capture_pageview: false if using SPA with manual pageview tracking
  • capture_pageleave: true for session duration accuracy
  • Reverse proxy configured to bypass ad blockers (see posthog-sdk-patterns)
  • posthog.debug() disabled in production (guarded by NODE_ENV)
  • autocapture configured to exclude noisy elements

Server-Side:

  • posthog.shutdown() called in SIGTERM handler and serverless function cleanup
  • Feature flags secure API key is passed through personalApiKey for server-side local evaluation
  • flushAt and flushInterval tuned (default 20/10s is fine for most apps)

Security:

  • Personal API key (phx_) never in client bundles or NEXT_PUBLIC_ vars
  • .env files in .gitignore
  • Separate PostHog project per environment
Step 1: Production SDK Configuration
typescript
// lib/posthog-production.ts
import { PostHog } from 'posthog-node';

const posthog = new PostHog(process.env.NEXT_PUBLIC_POSTHOG_KEY!, {
  host: process.env.POSTHOG_HOST || 'https://us.i.posthog.com',
  personalApiKey: process.env.POSTHOG_FEATURE_FLAGS_SECURE_API_KEY,
  flushAt: 20,
  flushInterval: 10000,
  requestTimeout: 10000,
  maxRetries: 3,
});

// Graceful shutdown
async function shutdown() {
  await posthog.shutdown();
  process.exit(0);
}
process.on('SIGTERM', shutdown);
process.on('SIGINT', shutdown);
Step 2: Graceful Degradation
typescript
// PostHog should never break your app — wrap all calls
function safeCapture(distinctId: string, event: string, properties?: Record<string, any>) {
  try {
    posthog.capture({ distinctId, event, properties });
  } catch (error) {
    // Log but never throw — analytics should not crash your app
    console.error('[PostHog] Capture failed:', (error as Error).message);
  }
}

async function safeGetFlag(flagKey: string, userId: string, defaultValue: boolean = false): Promise<boolean> {
  try {
    const result = await posthog.isFeatureEnabled(flagKey, userId);
    return result ?? defaultValue;
  } catch (error) {
    console.error('[PostHog] Flag evaluation failed:', (error as Error).message);
    return defaultValue; // Always return safe default
  }
}
Step 3: Health Check Endpoint
typescript
// api/health.ts (Next.js API route or Express handler)
// getPostHogDeliverySnapshot() reads application-owned counters maintained by
// the capture wrapper; it does not send a synthetic event on every health check.
export async function GET() {
  const delivery = getPostHogDeliverySnapshot();
  const degraded = delivery.errorRatio > delivery.reviewedErrorRatio
    || delivery.oldestQueuedEventMs > delivery.reviewedQueueAgeMs
    || delivery.flagFallbackRatio > delivery.reviewedFlagFallbackRatio;

  return Response.json({
    status: degraded ? 'degraded' : 'healthy',
    checks: {
      capture_delivery: delivery.captureStatus,
      queue_age_ms: delivery.oldestQueuedEventMs,
      flag_fallback_ratio: delivery.flagFallbackRatio,
      last_success_at: delivery.lastSuccessAt,
    },
  }, { status: degraded ? 503 : 200 });
}
Step 4: Serverless Function Pattern
typescript
// For Vercel Edge Functions, AWS Lambda, etc.
import { PostHog } from 'posthog-node';

export async function handler(request: Request) {
  // Create client per invocation in serverless (or use module-level singleton)
  const posthog = new PostHog(process.env.NEXT_PUBLIC_POSTHOG_KEY!, {
    host: 'https://us.i.posthog.com',
    flushAt: 1,       // Flush immediately in serverless
    flushInterval: 0,  // Don't wait
  });

  try {
    posthog.capture({
      distinctId: getUserId(request),
      event: 'api_called',
      properties: { endpoint: new URL(request.url).pathname },
    });

    const result = await doWork(request);
    return Response.json(result);
  } finally {
    // CRITICAL: Always flush before function exits
    await posthog.shutdown();
  }
}
Step 5: Pre-Flight Verification
bash
set -euo pipefail
: "${POSTHOG_PUBLIC_HOST:?Set the regional ingestion host for this project}"
: "${POSTHOG_PRIVATE_HOST:?Set the matching private API host}"

# 1. Verify PostHog is reachable from the release environment.
curl -sf "$POSTHOG_PUBLIC_HOST/healthz" && echo "PostHog: OK" || echo "PostHog: UNREACHABLE"

# 2. Verify the public project token through the non-capture flags endpoint.
curl -s -X POST "$POSTHOG_PUBLIC_HOST/flags?v=2" \
  -H 'Content-Type: application/json' \
  -d "{\"api_key\":\"$NEXT_PUBLIC_POSTHOG_KEY\",\"distinct_id\":\"deploy-check\"}" | jq '{flags, errorsParsingFlags}'

# 3. Verify private API access only when the integration requires it.
curl -sf "$POSTHOG_PRIVATE_HOST/api/projects/$POSTHOG_PROJECT_ID/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" | jq '.name' && echo "Admin API: OK"

Verify event delivery in a dedicated test project or with an explicitly approved synthetic production event. A 200 response confirms receipt and payload shape, not final ingestion; inspect quota_limited, ingestion warnings, and the resulting named event.

Show full SKILL.md (168 more words)Show less

Error Handling

AlertTriggerSeverityAction
PostHog capture failingApplication delivery error SLO breachedP3Check API host, queue, flush, and ingestion warnings
Flag evaluation breaches the service SLOReviewed service thresholdP2Inspect local evaluation, cache state, and remote fallback
Events not appearingExpected event freshness SLO breachedP2Check shutdown() is called, verify flush and warnings
Admin API 401Personal key rejectedP1Rotate key in PostHog settings

Rollback Procedure

bash
set -euo pipefail
# Quick rollback if PostHog causes issues
# Option 1: Disable PostHog via env var
kubectl set env deployment/app POSTHOG_ENABLED=false
kubectl rollout restart deployment/app

# Option 2: Roll back deployment
kubectl rollout undo deployment/app
kubectl rollout status deployment/app

Output

  • Production-hardened PostHog SDK configuration
  • Graceful degradation wrappers (never crash on analytics failure)
  • Read-only health endpoint based on application-owned delivery and fallback telemetry
  • Serverless shutdown pattern
  • Pre-flight verification commands

Examples

Before enabling production capture, verify the regional host, project-token scope, consent behavior, server lifecycle, flag defaults, proxy routes, release owner, and kill switch. Use a controlled test identity and report each check as pass, fail, or not applicable with evidence.

Resources

See official PostHog references for current authority and verification boundaries.

Next Steps

For version upgrades, see posthog-upgrade-migration.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/posthog-prod-checklist of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Posthog Prod Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Posthog Prod Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Posthog Prod Checklist this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
Monitoring Capture ServicePostHog/posthog40k—~5kAutomated safety check: PassCustom licence
Telemetry AnalyticsOpenHands/OpenHands91k—~305Automated safety check: PassMIT
Temps Best Practicesgotempsh/temps833—~2.9kAutomated safety check: PassApache-2.0
Exploring Apm TracesPostHog/posthog40k—~3.5kAutomated safety check: PassCustom licence
Exploring LLM TracesPostHog/posthog40k—~4.4kAutomated safety check: PassCustom licence

Similar skills

  • Official

    Guide for using the Grafana MCP to monitor and diagnose the capture service (rust/capture) in production.

    40k GitHub stars~5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Telemetry Analytics

    OpenHands/OpenHands

    This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts…

    91k GitHub stars~305 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Temps Best Practices

    gotempsh/temps

    Best-practices reference for preparing and instrumenting applications on Temps.

    833 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Exploring Apm Traces

    PostHog/posthog

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    40k GitHub stars~3.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Exploring LLM Traces

    PostHog/posthog

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    40k GitHub stars~4.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Configures the rollout shape of a PostHog experiment — the variant split (50/50, 80/20, A/B/C ratios), the overall rollout percentage that gates how many users enter the experiment, and the…

    40k GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Posthog Prod Checklist

What does Posthog Prod Checklist do?

Run a fail-safe production-readiness review for PostHog instrumentation, flags, secrets, privacy, delivery, and rollback. Posthog Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Run a fail-safe production-readiness review for PostHog instrumentation, flags, secrets, privacy, delivery, and rollback.

When should I use Posthog Prod Checklist?

Posthog Prod Checklist fits situations like: enabling a new production integration; major SDK change; with PostHog production checklist; postHog go-live.

How do I install Posthog Prod Checklist in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-prod-checklist -a claude-code`. Or copy the skill folder (skills/.curated/posthog-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/posthog-prod-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Posthog Prod Checklist in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-prod-checklist -a codex`. Or copy the skill folder (skills/.curated/posthog-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/posthog-prod-checklist in your project. Codex loads it when a task matches its description.

Can I use Posthog Prod Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-prod-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/posthog-prod-checklist, .gemini/skills/posthog-prod-checklist, .github/skills/posthog-prod-checklist and .opencode/skills/posthog-prod-checklist in your project.

What does Posthog Prod Checklist need to run?

Going by SKILL.md and its folder, Posthog Prod Checklist needs the command-line tools its instructions call (kubectl, curl and jq) and credentials named NEXT_PUBLIC_POSTHOG_KEY, POSTHOG_FEATURE_FLAGS_SECURE_API_KEY and POSTHOG_PERSONAL_API_KEY. Our summary lists: Node.js; A credential in NEXT_PUBLIC_POSTHOG_KEY; A credential in POSTHOG_FEATURE_FLAGS_SECURE_API_KEY. Its frontmatter pre-approves these tools: Read, Bash(kubectl:*), Bash(curl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Posthog Prod Checklist access the network?

SKILL.md names 3 domains. In commands or code: us.i.posthog.com; the agent is likely to contact it when it follows the instructions. As links in the text: posthog.com and status.posthog.com. This is read from the text; nothing was executed.

Is Posthog Prod Checklist safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Posthog Prod Checklist use?

Posthog Prod Checklist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Posthog Prod Checklist use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 204 tokens, read only when the agent opens those files.

What are the alternatives to Posthog Prod Checklist?

Skills that share tags, products or a category with Posthog Prod Checklist: Monitoring Capture Service (PostHog/posthog, 40k stars), Telemetry Analytics (OpenHands/OpenHands, 91k stars), Temps Best Practices (gotempsh/temps, 833 stars) and Exploring Apm Traces (PostHog/posthog, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Posthog Prod Checklist?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.