Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Explains what a member or a role can do in a PostHog project, using the access control MCP tools.
$ npx skills add PostHog/posthog-foss --skill checking-member-access -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PostHog/posthog-foss checking-member-access --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/products/access_control/skills/checking-member-access .claude/skills/checking-member-access && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "checking-member-access" agent skill from https://github.com/PostHog/posthog-foss/tree/master/products/access_control/skills/checking-member-access into .claude/skills/checking-member-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-member-access", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PostHog/posthog-foss/tree/master/products/access_control/skills/checking-member-accessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PostHog/posthog-foss --skill checking-member-access -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PostHog/posthog-foss checking-member-access --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .agents/skills && cp -r skills-src/products/access_control/skills/checking-member-access .agents/skills/checking-member-access && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "checking-member-access" agent skill from https://github.com/PostHog/posthog-foss/tree/master/products/access_control/skills/checking-member-access into .agents/skills/checking-member-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-member-access", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PostHog/posthog-foss --skill checking-member-access -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PostHog/posthog-foss checking-member-access --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/products/access_control/skills/checking-member-access .cursor/skills/checking-member-access && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "checking-member-access" agent skill from https://github.com/PostHog/posthog-foss/tree/master/products/access_control/skills/checking-member-access into .cursor/skills/checking-member-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-member-access", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PostHog/posthog-foss.git --path products/access_control/skills/checking-member-access--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PostHog/posthog-foss --skill checking-member-access -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PostHog/posthog-foss checking-member-access --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/products/access_control/skills/checking-member-access .gemini/skills/checking-member-access && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "checking-member-access" agent skill from https://github.com/PostHog/posthog-foss/tree/master/products/access_control/skills/checking-member-access into .gemini/skills/checking-member-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-member-access", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PostHog/posthog-foss checking-member-accessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PostHog/posthog-foss --skill checking-member-access -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .github/skills && cp -r skills-src/products/access_control/skills/checking-member-access .github/skills/checking-member-access && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "checking-member-access" agent skill from https://github.com/PostHog/posthog-foss/tree/master/products/access_control/skills/checking-member-access into .github/skills/checking-member-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-member-access", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PostHog/posthog-foss --skill checking-member-access -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PostHog/posthog-foss checking-member-access --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PostHog/posthog-foss.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/products/access_control/skills/checking-member-access .opencode/skills/checking-member-access && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "checking-member-access" agent skill from https://github.com/PostHog/posthog-foss/tree/master/products/access_control/skills/checking-member-access into .opencode/skills/checking-member-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-member-access", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
checking-member-accessExplains what a member or a role can do in a PostHog project, using the access control MCP tools.
Checking Member Access is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Explains what a member or a role can do in a PostHog project, using the access control MCP tools. Use when the user asks what someone can see or edit, who can edit dashboards or feature flags, why a member can or cannot open a dashboard, notebook or table, what a role grants, which properties are hidden from someone, or how the project's default access is set. Covers what each level means, how the stored rule, the enforced level and the inherited access relate, what the null values mean, which tool answers which…
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authorization and RBAC. It works with PostHog. The repository describes itself as: PostHog FOSS is a read-only mirror of PostHog, with all proprietary code removed. NOTE: This repo is synced automatically from the main PostHog repo. Please raise any issues and… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2c48221. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
posthog.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Checking Member Access loads about 3.2k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 1,476 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PostHog/posthog-foss at commit 2c48221, republished under its MIT licence (© PostHog). 1,476 words, ~3,215 tokens.
.claude/skills/checking-member-access/SKILL.md (or your agent's skills folder).Use this skill to answer "what can this person do here?" from the access control tools. The tools return the enforced level and where it comes from. This skill is for reading them correctly.
analyst role grant?" / "What is the default access in this project?"Not for changing rules. The read tools cannot write, and the settings page is where rules are edited.
source_subject of role anywhere in a
members-list result proves that role rules are enforced. Without that, ask the user whether the organization
is on Enterprise before walking roles in step 4 of the workflow.dashboard, insight, feature_flag, notebook,
experiment, warehouse_objects, and so on), then single objects inside a tool, then person and event
properties. The tool names are the keys of resources in a members-list entry.member can view and edit the resources their other rules permit. admin can also
edit project settings, manage the project's access rules, and delete the project.none cannot view. viewer can view but not change. editor can view and
change. manager can also manage the access rules of the tool or object. Order: none < viewer <
editor < manager.none hides the property. read shows it. read_write also allows edits. Every
property is read_write unless a rule exists.minimum and maximum per tool, on defaults-get, are the levels a rule can set. A tool
with minimum viewer can never be set to none.organization_level is a number: 1 member, 8 admin, 15 owner.viewer on
dashboards can still edit the dashboard they created, and cannot edit the others.effective_access_level and never recompute it from the stored rules. If the user asks why,
explain from inherited_access, not from your own precedence.| Tool | Returns |
|---|---|
posthog:access-control-members-list | Every member's enforced access to the project and to each tool. member_id narrows to a member. |
posthog:access-control-roles-list | The same per role. role_id narrows to a role. |
posthog:access-control-defaults-get | The project baseline, and which tools accept rules on single objects. |
posthog:access-control-member-objects-list | The object rules set for a member: every object with a rule for that member. |
posthog:access-control-member-properties-list | The property rules set for a member. |
posthog:access-control-role-objects-list | The object rules set for a role. |
posthog:access-control-role-properties-list | The property rules set for a role. |
posthog:access-control-default-objects-list | The object rules that apply to everyone in the project. |
posthog:access-control-default-properties-list | The property rules that apply to everyone in the project. |
posthog:org-members-list | Membership ids, names and organization levels. No project access details. |
posthog:roles-list, posthog:role-members-list | Role names by id, and who is in a role. |
All access control tools take an optional project id and default to the active project.
member_id is the organization membership id: the id from
org-members-list, or organization_membership_id from members-list. It is not the user id and not
the user uuid. role_id is the id from roles-list.members-list with member_id. effective_access_level for that tool
is the complete answer. It already includes the member's roles, the project default and the bypasses.inherited_access. See the table below. Only mention the stored
access_level when it differs from the enforced level.organization_level is 8 or 15 on the member's entry: full access, no rule applies.dashboard-get or insight-get, and
compare created_by.uuid with user.uuid on the member's entry.member-objects-list, role-objects-list for each id in the member's role_ids, and
default-objects-list, and pick out the rows for this object. Tell the user how many roles you
would walk and ask before doing it for a member in many roles.members-list without member_id, filtered on
resources.<tool>.effective_access_level. The response is every member times every tool and has no
pagination. For a large organization, ask which people the user cares about first, or answer per
member.| Field | Meaning |
|---|---|
access_level | The subject's own stored rule for this scope. null means no rule of its own. |
effective_access_level | What is enforced. null means nothing resolves for this scope. It is not "no access". |
inherited_access | The level the subject falls back to without a rule of its own, and where it comes from. null when nothing supplies one. |
inherited_access.source | resource or parent_resource for a tool rule, object or parent_object for an object rule, system_default for the PostHog default. org_admin and creator are the bypasses described above. org_membership appears only when the object is the organization itself. |
inherited_access.source_subject | member, role or default: whose rule supplied it. null when a bypass or the PostHog default did. |
How to phrase the answer:
source is org_admin: "This member is an organization admin and has full access to everything." The
stored rules do not apply to them.access_level is set and equals effective_access_level: "This member has an explicit rule: editor."access_level is null and source_subject is role: "This member has editor access, based on a role."
The role's name is not in the entry; roles-list has it if the user wants it.access_level is null and source_subject is default: "This member has viewer access, based on the
project default."source is system_default: "No rule is set anywhere, so the PostHog default applies."effective_access_level is null: "Nothing resolves for this tool here." Do not read it as no access.members-list is not proof of no access. A caller who is not an organization
admin, in an organization where members cannot see each other, only sees members with project-scoped
access.can_edit on the members and roles lists describes the caller, not the subject: whether the person
running the tool may change rules.available_project_levels and available_resource_levels are the vocabulary, lowest first. Use them
to compare levels instead of assuming an order.object_rule_resources on defaults-get lists the tools that accept rules on single objects. A tool
not in that list has no object rules to look for.© PostHog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in products/access_control/skills/checking-member-access of PostHog/posthog-foss.
Open the folder on GitHubat commit 2c48221
Checking Member Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Checking Member Access this skillPostHog/posthog-foss | 721 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| K8s Security PoliciesCybereason-Public/owLSM | 280 | 11 repos | ~2k | Automated safety check: Pass | GPL-2.0 | |
| Payloadpayloadcms/payload | 45k | 5 repos | ~6.2k | Automated safety check: Pass | MIT | |
| Convex Setup Authspokvulcan/poker-planning | 114 | 8 repos | ~1.8k | Automated safety check: Pass | MIT | |
| UI Auditbagofwords1/bagofwords | 458 | — | ~2.9k | Automated safety check: Pass | Custom licence |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
payloadcms/payload
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
spokvulcan/poker-planning
Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.
bagofwords1/bagofwords
Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…
SeemSeam/claude_codex_bridge
Diagnose a named CCB agent by combining authoritative runtime and job lineage with deep read-only pane inspection, apply bounded recovery when evidence supports it, verify the result, and request…
PostHog/posthog-foss
Author useful, low-noise log alerts on services in a PostHog project.
PostHog/posthog-foss
Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…
PostHog/posthog-foss
Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).
PostHog/posthog-foss
Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.
PostHog/posthog-foss
Debug and inspect LLM/AI agent traces using PostHog's MCP tools.
PostHog/posthog-foss
Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.
Works with
Categories
Explains what a member or a role can do in a PostHog project, using the access control MCP tools. Checking Member Access is an agent skill from PostHog/posthog-foss, published by the product's own GitHub organization. Explains what a member or a role can do in a PostHog project, using the access control MCP tools.
Checking Member Access fits situations like: the user asks what someone can see; who can edit dashboards; why a member can; cannot open a dashboard.
Run `npx skills add PostHog/posthog-foss --skill checking-member-access -a claude-code`. Or copy the skill folder (products/access_control/skills/checking-member-access in PostHog/posthog-foss) into .claude/skills/checking-member-access in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PostHog/posthog-foss --skill checking-member-access -a codex`. Or copy the skill folder (products/access_control/skills/checking-member-access in PostHog/posthog-foss) into .agents/skills/checking-member-access in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog-foss --skill checking-member-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checking-member-access, .gemini/skills/checking-member-access, .github/skills/checking-member-access and .opencode/skills/checking-member-access in your project.
SKILL.md names no scripts, command-line tools or credentials: Checking Member Access is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: posthog.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Checking Member Access is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Checking Member Access: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog-foss, which has 721 GitHub stars. The repository holds 213 skills in this directory. The repository was last updated on October 7, 2026.
Source: PostHog/posthog-foss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.