
Review Hog Perspective Contracts Security
作者 PostHog469d1773e9cb无许可证收录于 2026年10月8日更新于 2026年10月8日
The Contracts & Security review perspective for PostHog Review. Verifies that changed code is safe and maintains compatibility: API contracts and breaking changes, injection / authz / data exposure, input validation, and schema / interface alignment. Reports security and contract issues only.
添加到 SourceWeft 工作区
- 在控制台中打开该技能,并将它添加到工作区。
- 为需要使用它的对话启用该技能。
该技能仅含说明:不附带任何可执行的脚本。
添加到 SourceWeft系统会先要求你登录,然后直接带你回到这个技能。
让你的智能体来安装
把这段提示词粘贴到 Claude Code、Codex、Cursor 或其他能运行命令的智能体中,也可以粘贴到 SourceWeft 对话里。智能体会阅读这个技能的安装说明,向你展示它的来源、许可证和脚本情况,在你同意后用 SourceWeft CLI 安装。
阅读 https://sourceweft.com/skills/gh-posthog-ai-plugin-review-hog-perspective-contracts-security/install.md 中的说明,按说明安装这个技能。安装前先告诉我它的来源、许可证以及是否附带脚本,等我确认。修改我电脑上的其他任何内容之前也要先问我。用命令行自行安装
适用于 Claude Code、Codex、Cursor 及其他本地智能体。SourceWeft CLI 会从源代码仓库中获取此处扫描过的那次提交,并根据扫描时记录的哈希值逐一校验每个文件。只要有任何不一致,就不会写入任何内容。
npx @sourceweft/cli skills install gh-posthog-ai-plugin-review-hog-perspective-contracts-security添加 --agent claude-code、codex、cursor 或 universal 来选择安装给哪个智能体(默认为 Claude Code)。
上游安装器——未经 SourceWeft 校验
开源的 skills 安装器会获取同一个固定的提交,但不会根据 SourceWeft 记录的哈希值校验文件。
npx skills add https://github.com/PostHog/ai-plugin/tree/469d1773e9cb55cb2d0cffd0a91e12bbeff8d32e/skills/review-hog-perspective-contracts-security来源与署名
来源:PostHog/ai-plugin位于skills/review-hog-perspective-contracts-security提交469d177
许可证: 无许可证
内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。
更多来自 PostHog/ai-plugin 的技能

Writing Simplified Technical English
PostHog
应用 ASD-STE100 简化技术英语规则,让智能体撰写的文字含义明确、便于执行。

Working With Task Comments
PostHog
通过 PostHog MCP exec 调度器读取并解读 PostHog 任务、产物和画布上的评论。

Working With Skills
PostHog
指导智能体使用 PostHog 的 skill-* MCP 工具来发现、读取、创建、更新和重构技能。

Working With Scouts
PostHog
关于如何把监控任务委派给 PostHog Signals 侦察代理、处理其报告并长期调校整个代理集群的操作手册。

Validating And Publishing Canvases
PostHog
Validate and publish a canvas source project safely: the source-project shape, declared capabilities, reading the current version pointer, iterating on validation diagnostics, guarded publishing with expected_current_version_id, staging a draft build and promoting it, waiting out the queued build, and recovering from a 409 version_conflict or a 429 capacity limit without overwriting concurrent work. Use whenever a canvas edit is ready to save, a draft build is wanted, a canvas publish or build returns diagnostics or a conflict, or a task needs to understand canvas version history.

Understanding Billing Usage
PostHog
Explains PostHog billing usage and spend from the customer's visible Billing MCP tools. Use when the user asks why usage or spend is high, which product or project is driving usage, what a usage type means, how to reduce usage, what changed over time, why they got a usage change alert, or whether a spike/drop alert was real or noisy. Also use before product-specific analytics skills when the user names a billable PostHog product metric such as events, recordings, feature flag requests, exceptions, survey responses, synced rows, logs, AI events, AI credits, or Inbox credits. Starts from Billing usage/spend tools, then routes to customer-visible product MCP surfaces for deeper investigation.
更多Security技能

Dpop Adoption
指导为 Google OAuth 平台实现 OAuth 2.0 DPoP(RFC 9449)发送方约束刷新令牌。

Secops Triage
指导 SOC 分析师对 Google SecOps 安全告警进行分诊,从调查到关闭或升级。

Secops Investigate
指导 SOC 分析师在 Google SecOps 中使用 UDM 查询和时间线进行深入的安全事件与实体调查。

Secops Hunt
指导在 Google SecOps 中使用 UDM 查询、IoC 回溯、普遍性与异常分析进行主动威胁狩猎。

Secops Cases
通过 MCP 工具管理 Google Security Operations SOAR 案例的整个生命周期。

Iam Helper For Privileged Access Management
指导 Google Cloud Privileged Access Manager 的权限配置增删改查、临时访问申请与授权审批流程。