Agent skill

Posthog Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Secure PostHog tokens, hosts, proxy routes, captured properties, and private-API scopes across browser and server boundaries.

MITAuto-check: notes

Install Posthog Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace posthog-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/posthog-security-basics .claude/skills/posthog-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
posthog-security-basics
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
385 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Secure PostHog tokens, hosts, proxy routes, captured properties, and private-API scopes across browser and server boundaries.

  • Works in 6 steps: Understand Key Security Profiles → Create Scoped Personal API Keys → Rotate Personal API Keys → …
  • Reviewing secrets
  • SKILL.md covers Overview, Prerequisites, Instructions and Security Checklist, plus 5 more sections
  • Calls curl, vercel and jq; reaches us.posthog.com and us.i.posthog.com; needs POSTHOG_PERSONAL_API_KEY and NEXT_PUBLIC_POSTHOG_KEY

What it does

Posthog Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure PostHog tokens, hosts, proxy routes, captured properties, and private-API scopes across browser and server boundaries. Use when reviewing secrets or hardening an integration. Trigger with "PostHog security", "PostHog secret scan", or "PostHog API key review".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Designed for Claude Code

It works with PostHog. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Reviewing secrets
  • Hardening an integration
  • With PostHog security
  • PostHog secret scan

Example prompts

  • “PostHog security”
  • “PostHog secret scan”
  • “PostHog API key review”
  • “/posthog-security-basics”

Requirements

  • A credential in NEXT_PUBLIC_POSTHOG_KEY
  • A credential in POSTHOG_PERSONAL_API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Understand Key Security Profiles
  2. Create Scoped Personal API Keys
  3. Rotate Personal API Keys
  4. Prevent Key Leaks
  5. Server-Side Key Isolation
  6. Audit API Key Usage

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • vercel
    • jq
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • us.posthog.com
    • us.i.posthog.com

    Also links to:

    • posthog.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • POSTHOG_PERSONAL_API_KEY
    • NEXT_PUBLIC_POSTHOG_KEY
    • POSTHOG_FEATURE_FLAGS_SECURE_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Posthog Security Basics loads about 1.6k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 73 tokens; SKILL.md has 385 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:44
    # .env (NEVER commit)
  • NoteMentions a .env fileSKILL.md:50
    .env
  • NoteMentions a .env fileSKILL.md:51
    .env.local
  • NoteMentions a .env fileSKILL.md:52
    .env.*.local
  • NoteMentions a .env fileSKILL.md:156
    - [ ] `.env` files in `.gitignore`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 385 words, ~1,634 tokens.

Download SKILL.mdSave it as .claude/skills/posthog-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
posthog-security-basics
description
Secure PostHog tokens, hosts, proxy routes, captured properties, and private-API scopes across browser and server boundaries. Use when reviewing secrets or hardening an integration. Trigger with "PostHog security", "PostHog secret scan", or "PostHog API key review".
allowed-tools
Read, Write, Grep
compatibility
Designed for Claude Code
argument-hint
[project-path] [security-scope]
version
1.14.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, posthog, api, security, audit

PostHog Security Basics

Overview

Secure PostHog API key management, least-privilege access, and secret rotation. PostHog has two key types with very different security profiles: the Project API Key (phc_...) is intentionally public and safe to include in frontend bundles, while the Personal API Key (phx_...) grants admin access and must never be exposed.

Prerequisites

  • PostHog account with admin access
  • Understanding of environment variable management
  • .gitignore configured

Instructions

Tool discipline

Use Read to inspect the relevant configuration and implementation before proposing changes. Use Grep to locate initialization, capture, flag, and credential boundaries. Use Write only for a new, explicitly requested artifact inside the target project.

Step 1: Understand Key Security Profiles
Key TypePrefixExposure RiskCapabilities
Project API Keyphc_Low (designed to be public)Capture events, evaluate flags, identify users
Personal API Keyphx_Critical (full admin access)CRUD flags, read persons, query insights, delete data
bash
# .env (NEVER commit)
NEXT_PUBLIC_POSTHOG_KEY=phc_abc123   # Safe for frontend (NEXT_PUBLIC_ prefix)
POSTHOG_PERSONAL_API_KEY=phx_xyz789  # Server-only — NEVER in frontend code
POSTHOG_PROJECT_ID=12345

# .gitignore
.env
.env.local
.env.*.local
Step 2: Create Scoped Personal API Keys
bash
set -euo pipefail
# Create a read-only key for BI dashboards
curl -X POST "https://us.posthog.com/api/personal_api_keys/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "label": "bi-dashboard-readonly",
    "scopes": ["insight:read", "dashboard:read", "query:read"]
  }'

# Create a key scoped to feature flags only
curl -X POST "https://us.posthog.com/api/personal_api_keys/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "label": "feature-flag-service",
    "scopes": ["feature_flag:read", "feature_flag:write"]
  }'
Step 3: Rotate Personal API Keys
bash
set -euo pipefail
# 1. Create new key in PostHog Settings > Personal API Keys
# 2. Update secret in your deployment platform
# Vercel:
vercel env rm POSTHOG_PERSONAL_API_KEY production
vercel env add POSTHOG_PERSONAL_API_KEY production

# GitHub Actions:
gh secret set POSTHOG_PERSONAL_API_KEY --body "phx_new_key_here"

# 3. Verify new key works
curl -s "https://us.posthog.com/api/projects/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" | jq '.[0].name'

# 4. Delete old key in PostHog dashboard
Step 4: Prevent Key Leaks
bash
# Git pre-commit hook to catch PostHog personal keys
# .git/hooks/pre-commit (or use husky)
#!/bin/bash
if git diff --cached --diff-filter=ACM | grep -qE 'phx_[a-zA-Z0-9]{20,}'; then
  echo "ERROR: PostHog personal API key (phx_) detected in staged files!"
  echo "Remove it and use environment variables instead."
  exit 1
fi
yaml
# .github/secret-scanning.yml (or use GitHub's built-in secret scanning)
patterns:
  - name: PostHog Personal API Key
    regex: 'phx_[a-zA-Z0-9]{20,}'
    severity: critical
Step 5: Server-Side Key Isolation
typescript
// lib/posthog-server.ts — Personal key never leaves the server
import { PostHog } from 'posthog-node';

const posthog = new PostHog(process.env.NEXT_PUBLIC_POSTHOG_KEY!, {
  host: 'https://us.i.posthog.com',
  // The SDK option keeps its historical name; provide the server-only secure flag key.
  personalApiKey: process.env.POSTHOG_FEATURE_FLAGS_SECURE_API_KEY,
});

// API routes that proxy admin operations
// Never expose the personal key to the client
export async function getFeatureFlagsForUser(userId: string) {
  return posthog.getAllFlags(userId);
}
Step 6: Audit API Key Usage
bash
set -euo pipefail
# Check activity log for API key operations
curl "https://us.posthog.com/api/projects/$POSTHOG_PROJECT_ID/activity_log/" \
  -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" | \
  jq '[.results[] | select(.scope == "PersonalAPIKey") | {
    user: .user.email,
    activity: .activity,
    created_at
  }]'

Security Checklist

  • Project key (phc_) used for all frontend/capture code
  • Personal key (phx_) only on server, never in frontend bundles
  • .env files in .gitignore
  • Separate keys per environment (dev/staging/prod)
  • Scoped personal keys (not full admin for every service)
  • Git pre-commit hook scanning for phx_ keys
  • Key rotation documented and scheduled (quarterly)
Show full SKILL.md (158 more words)Show less

Error Handling

IssueDetectionFix
Personal key in git historyGitHub secret scanning alertRotate key immediately, revoke old one
Wrong key type401 on admin APIUse phx_ for admin, phc_ for capture
Overprivileged keyAudit log shows unexpected operationsCreate scoped key, revoke broad one
Key exposed in logsLog scrubbing finds phx_Redact logs, rotate key

Output

  • Environment-specific API key configuration
  • Scoped personal API keys for least privilege
  • Key rotation procedure
  • Git pre-commit hook for leak prevention
  • Audit log queries for key usage monitoring

Examples

For a leaked personal API key, revoke it in PostHog, search history and deployment logs for exposure, issue a least-privilege replacement, rotate affected integrations, and verify audit evidence. Do not treat the public project token as a secret, but still constrain where it can send data.

Resources

See official PostHog references for current authority and verification boundaries.

Next Steps

For production deployment, see posthog-prod-checklist.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/posthog-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Posthog Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Posthog Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Posthog Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: NotesMIT
Opik Analytics Instrumentationcomet-ml/opik22k—~4.4kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Define Feature Flagmacro-inc/macro4.6k—~780Automated safety check: PassAGPL-3.0
Soku CLIAbout-Intelligence/soku-cli305—~2.4kAutomated safety check: PassMIT
Compare Array Bundle SizePostHog/posthog-js633—~599Automated safety check: PassCustom licence

Similar skills

  • Shows how to add product analytics events to Opik's frontend, Java backend and Python SDK, all reporting through Segment to PostHog with an opik_ name prefix.

    22k GitHub stars~4.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Define Feature Flag

    macro-inc/macro

    Define a frontend feature flag with defineFlag and wire its readers.

    4.6k GitHub stars~780 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Soku CLI

    About-Intelligence/soku-cli

    Guides an agent through the soku command line tool for ads, GA4 and PostHog data reads, ads writes, SEO hosting, automations, files and skill management.

    305 GitHub stars~2.4k tokensUpdated today
    Marketing & SEOAuto-check passed
  • Compare Array Bundle Size

    PostHog/posthog-js

    Official

    Quickly compare the posthog-js array.js bundle size in the current working tree against a git baseline using the repository's esbuild proxy.

    633 GitHub stars~599 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Authoring Log Alerts

    PostHog/posthog

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Posthog Security Basics

What does Posthog Security Basics do?

Secure PostHog tokens, hosts, proxy routes, captured properties, and private-API scopes across browser and server boundaries. Posthog Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Secure PostHog tokens, hosts, proxy routes, captured properties, and private-API scopes across browser and server boundaries.

When should I use Posthog Security Basics?

Posthog Security Basics fits situations like: reviewing secrets; hardening an integration; with PostHog security; postHog secret scan.

How do I install Posthog Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/posthog-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/posthog-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Posthog Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-security-basics -a codex`. Or copy the skill folder (skills/.curated/posthog-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/posthog-security-basics in your project. Codex loads it when a task matches its description.

Can I use Posthog Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill posthog-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/posthog-security-basics, .gemini/skills/posthog-security-basics, .github/skills/posthog-security-basics and .opencode/skills/posthog-security-basics in your project.

What does Posthog Security Basics need to run?

Going by SKILL.md and its folder, Posthog Security Basics needs the command-line tools its instructions call (curl, vercel, jq and gh) and credentials named POSTHOG_PERSONAL_API_KEY, NEXT_PUBLIC_POSTHOG_KEY and POSTHOG_FEATURE_FLAGS_SECURE_API_KEY. Our summary lists: A credential in NEXT_PUBLIC_POSTHOG_KEY; A credential in POSTHOG_PERSONAL_API_KEY. Its frontmatter pre-approves these tools: Read, Write, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Posthog Security Basics access the network?

SKILL.md names 3 domains. In commands or code: us.posthog.com and us.i.posthog.com; the agent is likely to contact these when it follows the instructions. As links in the text: posthog.com. This is read from the text; nothing was executed.

Is Posthog Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Posthog Security Basics use?

Posthog Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Posthog Security Basics use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 202 tokens, read only when the agent opens those files.

What are the alternatives to Posthog Security Basics?

Skills that share tags, products or a category with Posthog Security Basics: Opik Analytics Instrumentation (comet-ml/opik, 22k stars), C15t (c15t/c15t, 1.9k stars), Define Feature Flag (macro-inc/macro, 4.6k stars) and Soku CLI (About-Intelligence/soku-cli, 305 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Posthog Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.