Official agent skill

Review Hog Perspective Contracts Security

by PostHog in PostHog/posthog

The Contracts & Security review perspective for PostHog Review.

OfficialCustom licenceAuto-check passedSecurity

Install Review Hog Perspective Contracts Security

skills CLI
$ npx skills add PostHog/posthog --skill review-hog-perspective-contracts-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PostHog/posthog review-hog-perspective-contracts-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PostHog/posthog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/products/review_hog/skills/review-hog-perspective-contracts-security .claude/skills/review-hog-perspective-contracts-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-hog-perspective-contracts-security
GitHub stars
40k
Token cost
~1k tokens
SKILL.md length
436 words
Files
1
Skills in repo
252
Repo updated
First seen
Licence
Custom licence

At a glance

The Contracts & Security review perspective for PostHog Review.

  • Works in 4 steps: API contracts & breaking changes → Security vulnerabilities → Input validation & boundaries → …
  • Tasks that involve API design
  • SKILL.md covers Primary investigation areas, Investigation commands, Where to focus and What to leave to other…, plus 2 more sections
  • Calls rg

What it does

Review Hog Perspective Contracts Security is an agent skill from PostHog/posthog, published by the product's own GitHub organization. The Contracts & Security review perspective for PostHog Review. Verifies that changed code is safe and maintains compatibility: API contracts and breaking changes, injection / authz / data exposure, input validation, and schema / interface alignment. Reports security and contract issues only.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering API design, Authorization and RBAC and Security review. It works with PostHog. The repository describes itself as: :hedgehog: PostHog is the leading platform for building self-driving products. Our developer tools – AI observability, analytics, session replay, flags, experiments, error…

When your agent uses it

  • Tasks that involve API design
  • Tasks that involve Authorization and RBAC
  • Tasks that involve Security review

Example prompts

  • “/review-hog-perspective-contracts-security”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. API contracts & breaking changes
  2. Security vulnerabilities
  3. Input validation & boundaries
  4. Schema & interface alignment

What it can do on your machine

Read from SKILL.md and the folder at commit 812e5c6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Hog Perspective Contracts Security loads about 1k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 436 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 436 words (~1,005 tokens).

“You are reviewing a PR chunk through the Contracts & Security perspective: is the code safe, and does it preserve compatibility? Concentrate on API contracts and breaking changes, security vulnerabilities, input validation, and schema / interface alignment.”

— opening of SKILL.md by PostHog, Custom licence
name
review-hog-perspective-contracts-security
metadata.owner_team
review_hog
metadata.perspective
contracts_security

Read the full SKILL.md on GitHub

Files

Just SKILL.md in products/review_hog/skills/review-hog-perspective-contracts-security of PostHog/posthog.

Open the folder on GitHubat commit 812e5c6

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in PostHog/posthog, which our catalogue first saw on October 8, 2026.

Compare with similar skills

Review Hog Perspective Contracts Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Hog Perspective Contracts Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Hog Perspective Contracts Security this skillPostHog/posthog40k—~1kAutomated safety check: PassCustom licence
API Security Best Practicesdavila7/claude-code-templates32k8 repos~5.8kAutomated safety check: PassMIT
Vercel Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT
Framer Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~767Automated safety check: NotesMIT
Review Securityhashgraph-online/awesome-codex-plugins1.3k—~601Automated safety check: PassApache-2.0
Security Review ChecklistZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT

Similar skills

  • API Security Best Practices

    davila7/claude-code-templates

    Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

    32k GitHub starsUsed in 8 repos~5.8k tokens
    Backend & APIsAuto-check passed
  • Vercel Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Vercel security best practices for secrets, headers, and access control.

    2.8k GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Framer Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Framer security best practices for secrets and access control.

    2.8k GitHub stars~767 tokensUpdated yesterday
    SecurityAuto-check: notes
  • Review Security

    hashgraph-online/awesome-codex-plugins

    Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks.

    1.3k GitHub stars~601 tokensUpdated today
    SecurityAuto-check passed
  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed
  • Absolute Audit

    maddhruv/absolute

    Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…

    218 GitHub starsUsed in 1 repo~1.2k tokens
    SecurityAuto-check passed

More from PostHog/posthog

All 252 skills in this repo
  • Authoring Log Alerts

    PostHog/posthog

    Official

    Author useful, low-noise log alerts on services in a PostHog project.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Official

    Operating procedure for the conflict-autoresolver agent: sweep open PostHog/posthog PRs that conflict with master, resolve the trivial conflicts (generated artifacts deterministically, source…

    40k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    40k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Exploring Apm Traces

    PostHog/posthog

    Official

    Investigates distributed application performance using PostHog APM (OpenTelemetry span) data via MCP.

    40k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Exploring LLM Traces

    PostHog/posthog

    Official

    Debug and inspect LLM/AI agent traces using PostHog's MCP tools.

    40k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Investigate Metric

    PostHog/posthog

    Official

    Diagnose why a product metric changed (dropped, spiked, or plateaued) by orchestrating breakdowns, actors, paths, lifecycle, retention, and annotations queries.

    40k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Questions about Review Hog Perspective Contracts Security

What does Review Hog Perspective Contracts Security do?

The Contracts & Security review perspective for PostHog Review. Review Hog Perspective Contracts Security is an agent skill from PostHog/posthog, published by the product's own GitHub organization. The Contracts & Security review perspective for PostHog Review.

When should I use Review Hog Perspective Contracts Security?

Review Hog Perspective Contracts Security fits situations like: tasks that involve API design; tasks that involve Authorization and RBAC; tasks that involve Security review.

How do I install Review Hog Perspective Contracts Security in Claude Code?

Run `npx skills add PostHog/posthog --skill review-hog-perspective-contracts-security -a claude-code`. Or copy the skill folder (products/review_hog/skills/review-hog-perspective-contracts-security in PostHog/posthog) into .claude/skills/review-hog-perspective-contracts-security in your project. Claude Code loads it when a task matches its description.

How do I install Review Hog Perspective Contracts Security in Codex?

Run `npx skills add PostHog/posthog --skill review-hog-perspective-contracts-security -a codex`. Or copy the skill folder (products/review_hog/skills/review-hog-perspective-contracts-security in PostHog/posthog) into .agents/skills/review-hog-perspective-contracts-security in your project. Codex loads it when a task matches its description.

Can I use Review Hog Perspective Contracts Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PostHog/posthog --skill review-hog-perspective-contracts-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-hog-perspective-contracts-security, .gemini/skills/review-hog-perspective-contracts-security, .github/skills/review-hog-perspective-contracts-security and .opencode/skills/review-hog-perspective-contracts-security in your project.

What does Review Hog Perspective Contracts Security need to run?

Going by SKILL.md and its folder, Review Hog Perspective Contracts Security needs the command-line tools its instructions call (rg).

Does Review Hog Perspective Contracts Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Hog Perspective Contracts Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Hog Perspective Contracts Security use?

Review Hog Perspective Contracts Security has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Review Hog Perspective Contracts Security use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Hog Perspective Contracts Security?

Skills that share tags, products or a category with Review Hog Perspective Contracts Security: API Security Best Practices (davila7/claude-code-templates, 32k stars), Vercel Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Framer Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Review Security (hashgraph-online/awesome-codex-plugins, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Hog Perspective Contracts Security?

PostHog (a GitHub organization, an official publisher) maintains it in PostHog/posthog, which has 40,200 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.

Source: PostHog/posthog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.