copying-flags-across-projects — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited copying-flags-across-projects (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill guides you through duplicating a feature flag from a source project into one or more target projects within the same PostHog organization.
cleaning-up-stale-feature-flags skill instead.You need the flag's key and the source project's id.
posthog:feature-flag-get-all in the source project to find the matching flag and read its key.Targets must be in the same organization as the source. Call posthog:projects-get to list available projects and confirm membership before issuing the copy.
For a multi-target copy, the tool accepts up to 50 target project ids in a single call. Successes and failures are reported per target, so a partial failure does not block the rest.
Call posthog:feature-flag-get-definition on the source flag and present a concise summary to the user before copying:
filters.groups[].properties[] — these will be remapped server-side, but the user should know whether the target project already has matching cohortshas_encrypted_payloads) or is remote configuration (is_remote_configuration)Default to the safest combination and ask the user to override only if they explicitly want different behavior:
If the user says "promote it as-is" or "turn it on in prod", switch disable_copied_flag to false. If they say "include the rollout schedule" or "with the scheduled rollout", switch copy_schedule to true.
Call posthog:feature-flags-copy-flags-create with:
feature_flag_key: the source flag's keyfrom_project: the source project idtarget_project_ids: the resolved list of target project idsdisable_copied_flag: from step 4 (default true)copy_schedule: from step 4 (default false)The response includes a success array (one entry per copied flag) and a failed array (per-target errors). Surface both:
active state in the target.If any targets failed, ask the user whether to retry the failed ones, skip them, or fix the underlying issue (e.g. grant access, then retry).
copy_schedule: true, any scheduled cohort references are remapped just like the live filter conditions.feature_flag:write (or feature_flag:*) scope. A *-only key will be rejected — this endpoint is gated by an INTERNAL viewset and * consent does not satisfy it. Team-scoped keys cannot reach this endpoint either; an org-scoped or unscoped key is required.failed array with a permission error.User: Copy the new-checkout flag from project 12345 to project 67890.>
Agent: Looking at the source flag in project 12345.
>
_(calls posthog:feature-flag-get-definition)_>
The new-checkout flag is currently a boolean at 25% rollout in project 12345, with no cohort filters and no scheduled changes. I'll copy it as disabled in project 67890 with no scheduled changes — this is the safer default. Confirm?>
User: Yes, but enable it in the target.
>
Agent: Got it — enabling in the target.
>
_(callsposthog:feature-flags-copy-flags-createwithdisable_copied_flag: false,copy_schedule: false)_
>
Done. Created flag id 99887 in project 67890 (active: true). No failed targets.posthog:feature-flags-copy-flags-create — performs the copy. Required fields: feature_flag_key, from_project, target_project_ids. Optional: disable_copied_flag, copy_schedule.posthog:feature-flag-get-all — find a flag by key/name in a given project when the user only gave a friendly name.posthog:feature-flag-get-definition — fetch the full source flag (filters, variants, cohort references, encryption flags) so you can preview before copying.posthog:projects-get — list projects in the active organization, used to resolve and validate target project ids.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.