Posthog Errors
aeonfun/aeon
Weekly cross-project error overview from PostHog - enumerates every project the OAuth grant covers, pulls the last 7 days of error-tracking issues per project, ranks them by impact, flags what's new…
Guidance for adding an API scope object to posthog/scopes.py and making it work for personal API keys, OAuth tokens and MCP clients.
$ npx skills add PostHog/posthog-foss --skill adding-api-scopes -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PostHog/posthog-foss adding-api-scopes --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/adding-api-scopes .claude/skills/adding-api-scopes && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "adding-api-scopes" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/adding-api-scopes into .claude/skills/adding-api-scopes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adding-api-scopes", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/adding-api-scopesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PostHog/posthog-foss --skill adding-api-scopes -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PostHog/posthog-foss adding-api-scopes --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/adding-api-scopes .agents/skills/adding-api-scopes && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "adding-api-scopes" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/adding-api-scopes into .agents/skills/adding-api-scopes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adding-api-scopes", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PostHog/posthog-foss --skill adding-api-scopes -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PostHog/posthog-foss adding-api-scopes --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/adding-api-scopes .cursor/skills/adding-api-scopes && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "adding-api-scopes" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/adding-api-scopes into .cursor/skills/adding-api-scopes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adding-api-scopes", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PostHog/posthog-foss.git --path .agents/skills/adding-api-scopes--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PostHog/posthog-foss --skill adding-api-scopes -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PostHog/posthog-foss adding-api-scopes --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/adding-api-scopes .gemini/skills/adding-api-scopes && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "adding-api-scopes" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/adding-api-scopes into .gemini/skills/adding-api-scopes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adding-api-scopes", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PostHog/posthog-foss adding-api-scopesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PostHog/posthog-foss --skill adding-api-scopes -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/adding-api-scopes .github/skills/adding-api-scopes && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "adding-api-scopes" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/adding-api-scopes into .github/skills/adding-api-scopes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adding-api-scopes", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PostHog/posthog-foss --skill adding-api-scopes -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PostHog/posthog-foss adding-api-scopes --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/adding-api-scopes .opencode/skills/adding-api-scopes && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "adding-api-scopes" agent skill from https://github.com/PostHog/posthog-foss/tree/master/.agents/skills/adding-api-scopes into .opencode/skills/adding-api-scopes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "adding-api-scopes", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
adding-api-scopesGuidance for adding an API scope object to posthog/scopes.py and making it work for personal API keys, OAuth tokens and MCP clients.
Adding API Scopes is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Guidance for adding an API scope object to posthog/scopes.py and making it work for personal API keys, OAuth tokens and MCP clients. Use when adding a scope object, exposing a viewset or MCP tool to tokens, moving a viewset off scopeobject = "INTERNAL", deciding if a scope is internal, OAuth-hidden or privileged, choosing a scope group, reading the scope list in Python, the frontend or the MCP server, or when a scope test fails in scopes.test.ts, testscopes.py or tool-filtering.test.ts. Trigger terms: new scope…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering MCP servers and OAuth and OpenID Connect. It works with Model Context Protocol, PostHog and Python. The repository describes itself as: PostHog FOSS is a read-only mirror of PostHog, with all proprietary code removed. NOTE: This repo is synced automatically from the main PostHog repo. Please raise any issues and… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2c48221. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Adding API Scopes loads about 2.1k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 1,163 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PostHog/posthog-foss at commit 2c48221, republished under its MIT licence (© PostHog). 1,163 words, ~2,140 tokens.
.claude/skills/adding-api-scopes/SKILL.md (or your agent's skills folder).A scope has two parts: an object and an action, as in feature_flag:read.
Adding a scope means adding a scope object, such as feature_flag. It gives tokens feature_flag:read and feature_flag:write.
posthog/scopes.py is the source of the object list.
The frontend type and the MCP OAuth list are generated from it.
The picker rows and the groups are kept by hand in frontend/src/lib/scopes.tsx, and a test checks them.
They stay in the frontend on purpose: labels, plurals, groups and picker omissions are UI decisions, while posthog/scopes.py decides what exists and what it grants.
Most endpoints fit an existing scope, for example insight:read.
Add a new scope only for a product area that a person wants to grant or withhold on its own, on a key or an OAuth app.
Name its object with a snake_case singular noun, such as feature_flag.
INTERNAL_API_SCOPE_OBJECTS.OAUTH_HIDDEN_SCOPE_OBJECTS.llm_gateway. Use PRIVILEGED_SCOPES, and set unprivilegedExcluded: true on the picker row.Then decide two more things, separately from the kind:
PROJECT_SECRET_API_KEY_ALLOWED_API_SCOPE_ACTION, in both posthog/scopes.py and frontend/src/lib/scopes.tsx. Read /adding-project-secret-api-key-auth first.ACCESS_CONTROL_RESOURCES in products/access_control/backend/facade/user_access_control.py. Access control resources use scope object names by design, so a viewset's scope_object names both its token scope and its access control resource. Do not give access control a naming or a type of its own. The resource fields of the access control serializers take GRANTABLE_API_SCOPE_OBJECTS as their choices, and the frontend APIScopeObject type is generated from those fields (be careful: the personal API key modal, the OAuth consent screen, CLI login and the key presets also use that type).APIScopeObject literal in posthog/scopes.py. If you chose internal, OAuth-hidden or privileged above, also add it to that set.scope_object = "<object>" on each viewset the scope covers.list and retrieve need :read, and create, update and destroy need :write.@action needs required_scopes, for example required_scopes=["<object>:write"]. Use :read if it only reads data, and :write if it changes data. Without it, token requests get a 403.scope_object = "INTERNAL" accepts only logged-in sessions. Change it to the new object to open it to tokens.hogli build:openapi, which carries the object to the frontend type, and hogli build:projections, which updates the OAuth lists of the MCP server and the web app. DO NOT EDIT GENERATED FILES BY HAND.frontend/src/lib/scopes.tsx:API_SCOPES with a sentence-case label and plural (/writing-user-facing-copy). Disable write if no endpoint writes. If the key modal should not offer the object, add a reason to API_SCOPES_OMITTED_FROM_MODAL instead.API_SCOPE_GROUPS. See "Choose a group".scopes: in products/<product>/mcp/tools.yaml.The OAuth consent screen and the scope pickers show objects in groups, from API_SCOPE_GROUPS in frontend/src/lib/scopes.tsx.
The groups make a long list readable, so a person can find a product quickly.
frontend/src/lib/scopes.test.ts, the coverage test: a grantable object has no picker row and no omission reason. Add a row to API_SCOPES, or a reason to API_SCOPES_OMITTED_FROM_MODAL. If the object is missing from APIScopeObject, run hogli build:openapi first. If the object is OAuth-hidden, run hogli build:projections instead, so the test learns to skip it.frontend/src/lib/scopes.test.ts, the group test: an object is in no group, or in two groups. Put it in exactly one group of API_SCOPE_GROUPS. It also fails when an OAuth-hidden object has a row or a group. Remove them, because no picker shows a hidden object.posthog/test/test_scopes.py: an internal, OAuth-hidden or privileged scope leaks into a list it must stay out of, or the project secret API key list in posthog/scopes.py differs from the copy in frontend/src/lib/scopes.tsx. Fix the set, or make the two lists equal.services/mcp/tests/unit/tool-filtering.test.ts, the completeness test: an MCP tool requires a scope that OAuth does not advertise. If the scope is new, run hogli build:projections. If it is internal, add it to the test's server-only list. Otherwise fix the scope name in tools.yaml.@action without required_scopes. Tokens get a 403.scope_object.Use these instead of writing your own list of scopes.
posthog.scopes.API_SCOPE_OBJECTS: every object, internal ones too.GRANTABLE_API_SCOPE_OBJECTS: the objects a person can grant.ALL_SCOPES: the grantable object:action strings.get_oauth_scopes_supported(): what the OAuth server advertises.APIScopeObject from ~/types.Object.values(ScopeObjectEnumApi), from products/access_control/frontend/generated/api.schemas.API_SCOPES, API_SCOPE_GROUPS and getScopeDescription from lib/scopes.OAUTH_SCOPES_SUPPORTED and OAUTH_SCOPES_HIDDEN, from lib/oauthScopes.generated in the web app and services/mcp/src/lib/oauth-scopes.generated.ts in the MCP server. The two files are the same.© PostHog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/adding-api-scopes of PostHog/posthog-foss.
Open the folder on GitHubat commit 2c48221
Adding API Scopes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Adding API Scopes this skillPostHog/posthog-foss | 721 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Posthog Errorsaeonfun/aeon | 767 | — | ~4.3k | Automated safety check: Warn | MIT | |
| Review Security ReportPrefectHQ/fastmcp | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Xquik MCPXquik-dev/x-twitter-scraper | 209 | — | ~997 | Automated safety check: Pass | MIT | |
| Kingdee MCP DevWaHaiLong/KingdeeMCP | 103 | — | ~853 | Automated safety check: Pass | MIT | |
| MCP Dart Streamable HTTPleehack/mcp_dart | 116 | — | ~2k | Automated safety check: Pass | MIT |
aeonfun/aeon
Weekly cross-project error overview from PostHog - enumerates every project the OAuth grant covers, pulls the last 7 days of error-tracking issues per project, ranks them by impact, flags what's new…
PrefectHQ/fastmcp
Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.
Xquik-dev/x-twitter-scraper
Connect, verify, and troubleshoot Xquik's remote MCP server.
WaHaiLong/KingdeeMCP
Knowledge base for the Kingdee MCP Dev Squad. An agent skill from WaHaiLong/KingdeeMCP.
leehack/mcp_dart
A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…
unifapi-agent/agents
A skill your agent uses when working with UnifAPI public-data APIs or the UnifAPI MCP server: connecting OAuth MCP clients, discovering operations, calling social/search/scrape/news APIs…
PostHog/posthog-foss
Author useful, low-noise log alerts on services in a PostHog project.
PostHog/posthog-foss
Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…
PostHog/posthog-foss
Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).
PostHog/posthog-foss
Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.
PostHog/posthog-foss
Debug and inspect LLM/AI agent traces using PostHog's MCP tools.
PostHog/posthog-foss
Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.
Works with
Categories
Guidance for adding an API scope object to posthog/scopes.py and making it work for personal API keys, OAuth tokens and MCP clients. Adding API Scopes is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization.py and making it work for personal API keys, OAuth tokens and MCP clients.
Adding API Scopes fits situations like: adding a scope object; exposing a viewset; MCP tool to tokens; moving a viewset off scopeobject = INTERNAL.
Run `npx skills add PostHog/posthog-foss --skill adding-api-scopes -a claude-code`. Or copy the skill folder (.agents/skills/adding-api-scopes in PostHog/posthog-foss) into .claude/skills/adding-api-scopes in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PostHog/posthog-foss --skill adding-api-scopes -a codex`. Or copy the skill folder (.agents/skills/adding-api-scopes in PostHog/posthog-foss) into .agents/skills/adding-api-scopes in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog-foss --skill adding-api-scopes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adding-api-scopes, .gemini/skills/adding-api-scopes, .github/skills/adding-api-scopes and .opencode/skills/adding-api-scopes in your project.
SKILL.md names no scripts, command-line tools or credentials: Adding API Scopes is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Adding API Scopes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Adding API Scopes: Posthog Errors (aeonfun/aeon, 767 stars), Review Security Report (PrefectHQ/fastmcp, 28k stars), Xquik MCP (Xquik-dev/x-twitter-scraper, 209 stars) and Kingdee MCP Dev (WaHaiLong/KingdeeMCP, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog-foss, which has 721 GitHub stars. The repository holds 213 skills in this directory. The repository was last updated on October 7, 2026.
Source: PostHog/posthog-foss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.