Official agent skill

Auditing Endpoints

by PostHog in PostHog/posthog-foss

Audit every endpoint in a PostHog project for staleness, failed materialisations, and unused materialised versions.

OfficialMITAuto-check passed

Install Auditing Endpoints

skills CLI
$ npx skills add PostHog/posthog-foss --skill auditing-endpoints -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog-foss auditing-endpoints --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/products/endpoints/skills/auditing-endpoints .claude/skills/auditing-endpoints && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-endpoints
GitHub stars
721
Token cost
~2.9k tokens
SKILL.md length
867 words
Files
1
Skills in repo
213
Repo updated
First seen
Licence
MIT

At a glance

Audit every endpoint in a PostHog project for staleness, failed materialisations, and unused materialised versions.

  • Works in 5 steps: List endpoints and their metadata → Pull usage from query_log → Check materialisation health and unused… → …
  • The user asks what endpoints can I clean up?
  • SKILL.md covers When to use this skill, Available tools, What counts as an issue and Workflow, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Auditing Endpoints is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Audit every endpoint in a PostHog project for staleness, failed materialisations, and unused materialised versions. Use when the user asks "what endpoints can I clean up?", "are any of my endpoints broken?", "which materialised versions are still being called?", or wants a one-shot cleanup pass over the Endpoints product. Produces a prioritised report grouped by issue type, with recommended actions but does not modify anything without explicit confirmation.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with PostHog. The repository describes itself as: PostHog FOSS is a read-only mirror of PostHog, with all proprietary code removed. NOTE: This repo is synced automatically from the main PostHog repo. Please raise any issues and… The licence is MIT.

When your agent uses it

  • The user asks what endpoints can I clean up?
  • Are any of my endpoints broken?
  • Which materialised versions are still being called?
  • Wants a one-shot cleanup pass over the Endpoints product

Example prompts

  • “what endpoints can I clean up?”
  • “are any of my endpoints broken?”
  • “which materialised versions are still being called?”
  • “/auditing-endpoints”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. List endpoints and their metadata
  2. Pull usage from query_log
  3. Check materialisation health and unused versions
  4. Present the audit
  5. Offer the next step

What it can do on your machine

Read from SKILL.md and the folder at commit 2c48221. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditing Endpoints loads about 2.9k tokens when it runs. Until then it costs about 120 tokens; SKILL.md has 867 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PostHog/posthog-foss at commit 2c48221, republished under its MIT licence (© PostHog). 867 words, ~2,889 tokens.

Download SKILL.mdSave it as .claude/skills/auditing-endpoints/SKILL.md (or your agent's skills folder).
name
auditing-endpoints
description
Audit every endpoint in a PostHog project for staleness, failed materialisations, and unused materialised versions. Use when the user asks "what endpoints can I clean up?", "are any of my endpoints broken?", "which materialised versions are still being called?", or wants a one-shot cleanup pass over the Endpoints product. Produces a prioritised report grouped by issue type, with recommended actions but does not modify anything without explicit confirmation.

Auditing endpoints

This skill produces a project-wide audit of the Endpoints product. Use it when the user wants to find what to clean up — unused endpoints, failing materialisations, materialised versions that nobody calls any more. It does not modify anything; it reports.

The deeper investigation per endpoint is diagnosing-endpoint-performance. The audit's job is to find candidates and hand off.

When to use this skill

  • "Audit my endpoints" / "What endpoints can I clean up?"
  • The user is taking over a project and wants to know what they've inherited
  • A periodic review (monthly / quarterly) of endpoint sprawl
  • The user is over a materialisation cost budget and wants to know what to disable

The dedicated tools give a fast endpoint-level view. For call frequency, recency, and cost over time, query the query_log table with execute-sql (endpoint-level). Per-version recency comes from endpoint-versions — each version carries its own last_executed_at.

Available tools

ToolWhat it's for
execute-sql (HogQL)Primary read path. Query system.data_modeling_endpoints for metadata (name, is_active, current_version, derived_from_insight, last_executed_at) and query_log for endpoint-level usage (call counts, recency, duration, bytes)
endpoint-materialization-statusPer endpoint: is materialisation eligible, current status, last run, last error (not in the system tables — use this tool)
endpoint-versionsAll versions for one endpoint, latest first, with each version's query, materialisation state, and last_executed_at
endpoint-updateWrite path — disable (is_active: false) or unmaterialise (is_materialized: false) after the user confirms
agent-feedbackTell the PostHog team what's missing or confusing in this flow so the product and skill improve

Prefer reading from the system tables over the endpoints-get-all / endpoint-get tools — one SQL query returns the whole inventory and lets you join metadata to usage in query_log.

What counts as an issue

CategoryTriggerTypical action
Never calledNo rows in query_log for the endpoint (personal-API-key calls only)Confirm with the user, then disable
Stalequery_log shows the last call more than 30 days agoConfirm with the user; often safe to disable
Inactiveis_active = 0 in system.data_modeling_endpointsVerify intent; if abandoned, delete
Failing materialisationendpoint-materialization-status returns Failed with an errorHand off to diagnosing-endpoint-performance
Unused materialised versionA materialised version whose last_executed_at (from endpoint-versions) is null or long staleUnmaterialise that version, or roll to a newer one
Drifted versionsMany versions exist (query changed repeatedly)History noise — not an issue, but worth noting

Usage counts only personal-API-key calls — an endpoint exercised solely from the Playground tab or the app will look unused. Per-version last_executed_at is recorded only for runs since that tracking was added, so a version can read null while still being used; always confirm before removing.

Workflow

1. List endpoints and their metadata

One execute-sql query gets the whole inventory from system.data_modeling_endpoints:

sql
SELECT name, is_active, current_version, derived_from_insight, last_executed_at
FROM system.data_modeling_endpoints
ORDER BY name

No rows → the project has no endpoints; say so and stop. Don't invent issues. (The last_executed_at column here is a convenience endpoint-level timestamp; for call frequency and cost, use query_log in the next step.)

2. Pull usage from query_log

query_log records every personal-API-key call, tagged with the endpoint name. One query gives recency and call counts across all endpoints:

sql
SELECT name, count() AS calls, max(query_start_time) AS last_called
FROM query_log
WHERE endpoint LIKE '%/endpoints/%' AND is_personal_api_key_request
GROUP BY name
ORDER BY name

Cross-reference with step 1:

  • In metadata, absent from query_log → never called via API key
  • Last call more than 30 days ago → stale

query_log also exposes query_duration_ms, read_rows, and read_bytes per call — useful to flag expensive endpoints in the same pass. This is endpoint-level; per-version recency comes from endpoint-versions (step 3).

Show full SKILL.md (320 more words)Show less
3. Check materialisation health and unused versions

For each materialised endpoint, call endpoint-materialization-status (this isn't in the system tables). Surface any with status: "Failed" separately — these are active failures, not staleness.

Then call endpoint-versions and read each version's last_executed_at: a materialised version that's null or long stale is an unused-materialised-version candidate. Treat this as a lead, not proof — per-version recency only counts API-key runs since tracking was added, so confirm with the user before unmaterialising.

4. Present the audit

Render a prioritised report grouped by category. Don't dump raw JSON; use a readable table per section:

text
## Endpoints audit — 9 issues

### 🔴 Failing materialisations (1)
- weekly_revenue (v3) — Failed 2h ago, "Column 'event_date' does not exist"
  → hand off to diagnosing-endpoint-performance

### 🟠 Never called via API key (3)
- internal_admin_query — created 5 months ago
- legacy_signup_funnel — created 1 year ago, materialised
- experiment_arm_lookup — created 9 months ago

### 🟠 Unused materialised versions (2)  [from endpoint-versions]
- monthly_active_users — v3 materialised, last_executed_at null (currently on v4 — unmaterialise v3)
- order_summary — v1 materialised, last_executed_at null

### 🟡 Stale (3)
- holiday_promo_2024 — last called 4 months ago
- ab_test_phase_1 — last called 2 months ago
- daily_revenue_cohort — last called 45 days ago

Recommended order:
1. Investigate the failing materialisation (blocks fresh data)
2. Unmaterialise the unused versions (free storage + compute)
3. Disable the never-called endpoints (if user confirms)
4. Review stale endpoints with the user

The exact format is less important than: prioritised, grouped, actionable, and hand-off clear.

5. Offer the next step

End with a clear question, not a decision:

  • "Want me to unmaterialise the unused versions?" — needs endpoint-update with is_materialized: false per version
  • "Want me to disable the never-called endpoints?" — needs endpoint-update with is_active: false
  • "Want me to dig into the failing materialisation?" — hands off to diagnosing-endpoint-performance

Never act from the audit alone. Disabling or unmaterialising affects external API consumers; always confirm before modifying.

Example interaction

text
User: "Audit my endpoints"

Agent steps:
- execute-sql on system.data_modeling_endpoints → 12 endpoints (4 materialised)
- execute-sql on query_log grouped by name → 8 endpoints have calls
- endpoint-materialization-status on each materialised endpoint → 1 failing
- endpoint-versions on the materialised ones → order_summary v2's last_executed_at is null

- Report:
  "Found 6 things worth looking at across 12 endpoints:

   🔴 Failing materialisations (1)
   - monthly_active_users (v2) — materialisation failed yesterday with
     'memory limit exceeded'. The endpoint is still callable inline but
     responses will be slower.

   🟠 Never called via API key (3)
   - legacy_funnel_v1 — created 11 months ago
   - test_export — created 3 months ago
   - admin_dump — created 8 months ago, materialised (wasteful)

   🟠 Unused materialised versions (1)  [from endpoint-versions]
   - order_summary v2 — materialised but its last_executed_at is null
     while v3 is current. Likely safe to unmaterialise v2.

   🟡 Stale (1)
   - holiday_2024 — last called 5 months ago

   Caveat: usage only counts personal-API-key calls; playground and
   dashboard runs aren't counted. Per-version recency comes from
   endpoint-versions and is sparse. Confirm before disabling.

   Want me to start with the failing materialisation, or clean up the
   unused version first?"

Important notes

  • The audit is read-only. Never call destructive tools from this flow. Hand off or confirm before any modification.
  • Empty = healthy. Don't pad an empty report with theoretical issues. "Nothing to clean up" is a good answer.
  • Read with SQL, drill in with the version tool. system.data_modeling_endpoints (metadata) and query_log (endpoint-level call counts, recency, cost) via execute-sql answer most of the audit. Per-version recency comes from endpoint-versions (each version's last_executed_at).
  • API-key-only scope. Usage only counts personal-API-key calls. An endpoint exercised only from the Playground tab or the app will look unused. Always confirm before acting.
  • Materialisation costs storage and compute. When an endpoint no longer needs materialisation, the cheapest fix is endpoint-update with is_materialized: false — not deleting the endpoint.
  • Inactive ≠ stale. An endpoint with is_active: false was deliberately turned off. Don't recommend deletion unless the user confirms it's truly abandoned.

© PostHog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in products/endpoints/skills/auditing-endpoints of PostHog/posthog-foss.

Open the folder on GitHubat commit 2c48221

Compare with similar skills

Auditing Endpoints next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditing Endpoints compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditing Endpoints this skillPostHog/posthog-foss721—~2.9kAutomated safety check: PassMIT
Opik Analytics Instrumentationcomet-ml/opik22k—~4.4kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Define Feature Flagmacro-inc/macro4.6k—~780Automated safety check: PassAGPL-3.0
Soku CLIAbout-Intelligence/soku-cli304—~2.4kAutomated safety check: PassMIT
Compare Array Bundle SizePostHog/posthog-js613—~599Automated safety check: PassCustom licence

Similar skills

  • Shows how to add product analytics events to Opik's frontend, Java backend and Python SDK, all reporting through Segment to PostHog with an opik_ name prefix.

    22k GitHub stars~4.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Define Feature Flag

    macro-inc/macro

    Define a frontend feature flag with defineFlag and wire its readers.

    4.6k GitHub stars~780 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Soku CLI

    About-Intelligence/soku-cli

    Guides an agent through the soku command line tool for ads, GA4 and PostHog data reads, ads writes, SEO hosting, automations, files and skill management.

    304 GitHub stars~2.4k tokensUpdated 2 days ago
    Marketing & SEOAuto-check passed
  • Compare Array Bundle Size

    PostHog/posthog-js

    Official

    Quickly compare the posthog-js array.js bundle size in the current working tree against a git baseline using the repository's esbuild proxy.

    613 GitHub stars~599 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Telemetry Analytics

    OpenHands/OpenHands

    This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts…

    90k GitHub stars~305 tokensUpdated today
    DevOps & CloudAuto-check passed

More from PostHog/posthog-foss

All 213 skills in this repo
  • Authoring Log Alerts

    PostHog/posthog-foss

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    721 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Autoresolving PR Conflicts

    PostHog/posthog-foss

    Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    721 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    721 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog-foss

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    721 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog-foss

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    721 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog-foss

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    721 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Questions about Auditing Endpoints

What does Auditing Endpoints do?

Audit every endpoint in a PostHog project for staleness, failed materialisations, and unused materialised versions. Auditing Endpoints is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Audit every endpoint in a PostHog project for staleness, failed materialisations, and unused materialised versions.

When should I use Auditing Endpoints?

Auditing Endpoints fits situations like: the user asks what endpoints can I clean up?; are any of my endpoints broken?; which materialised versions are still being called?; wants a one-shot cleanup pass over the Endpoints product.

How do I install Auditing Endpoints in Claude Code?

Run `npx skills add PostHog/posthog-foss --skill auditing-endpoints -a claude-code`. Or copy the skill folder (products/endpoints/skills/auditing-endpoints in PostHog/posthog-foss) into .claude/skills/auditing-endpoints in your project. Claude Code loads it when a task matches its description.

How do I install Auditing Endpoints in Codex?

Run `npx skills add PostHog/posthog-foss --skill auditing-endpoints -a codex`. Or copy the skill folder (products/endpoints/skills/auditing-endpoints in PostHog/posthog-foss) into .agents/skills/auditing-endpoints in your project. Codex loads it when a task matches its description.

Can I use Auditing Endpoints in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog-foss --skill auditing-endpoints -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-endpoints, .gemini/skills/auditing-endpoints, .github/skills/auditing-endpoints and .opencode/skills/auditing-endpoints in your project.

What does Auditing Endpoints need to run?

SKILL.md names no scripts, command-line tools or credentials: Auditing Endpoints is instructions for the agent only.

Does Auditing Endpoints access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Auditing Endpoints safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auditing Endpoints use?

Auditing Endpoints is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditing Endpoints use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auditing Endpoints?

Skills that share tags, products or a category with Auditing Endpoints: Opik Analytics Instrumentation (comet-ml/opik, 22k stars), C15t (c15t/c15t, 1.9k stars), Define Feature Flag (macro-inc/macro, 4.6k stars) and Soku CLI (About-Intelligence/soku-cli, 304 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditing Endpoints?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog-foss, which has 721 GitHub stars. The repository holds 213 skills in this directory. The repository was last updated on October 7, 2026.

Source: PostHog/posthog-foss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.