downloading-batch-export-files — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited downloading-batch-export-files (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill when a user wants a one-off downloadable export of PostHog data. The export is started and monitored through MCP, but the final file download uses the existing REST endpoint directly.
| Tool | Purpose |
|---|---|
posthog:file-download-batch-exports-create | Start an on-demand export and return the run ID |
posthog:file-download-batch-exports-retrieve | Poll the run status and return file IDs after completion |
Do not rely on a generated MCP tool for the /download/ endpoint. That endpoint is a redirecting file download endpoint, so raw HTTP/download handling is the right interface until MCP has explicit redirect support.
Ask a short clarifying question if the user did not specify the required inputs:
model: one of events, persons, or sessionsdata_interval_start and data_interval_end: ISO 8601 datetimes; the range must be at most one weekfile.format: Parquet or JSONLines; prefer Parquet for compact analytics exports and JSONLines for line-oriented text processingfile.compression: optional, one of zstd, gzip, brotli, lz4, or snappy. If JSONLines was chosen as format, only gzip and brotli are supported.file.max_size_mb: optional maximum part size in MB; set this when the user wants multiple smaller files instead of a single (potentially large) file.For events, include and exclude are optional event-name filters. Use them only when the user asks for specific events or wants to omit specific events.
Call posthog:file-download-batch-exports-create with the selected shape. The response contains an id for the export run.
Example request:
{
"model": "events",
"file": {
"format": "JSONLines",
"compression": "gzip"
},
"include": ["$pageview"],
"data_interval_start": "2026-05-25T00:00:00Z",
"data_interval_end": "2026-05-26T00:00:00Z"
}Call posthog:file-download-batch-exports-retrieve with the returned id.
Status handling:
| Status | Action |
|---|---|
Starting or Running | Wait briefly and poll again |
Completed | Read the files array and download each file |
Cancelled | Stop and report that the run was cancelled |
Failed, FailedRetryable, FailedBilling, Terminated, or TimedOut | Stop and report the error field |
When Completed, the files array contains file UUIDs. For single-file exports it usually contains one UUID. For split exports, download every UUID unless the user asked for a specific part.
If required by the user, a running export can be cancelled by calling posthog:file-download-batch-exports-cancel-create with the returned id.
An export that has already finished or has already failed may not be cancelled.
After cancelling an export, the id may not be used anymore and the export must start again from the beginning. However, you may still use the id to retrieve the export status (which will always be Cancelled).
Use a direct authenticated HTTP request to the existing endpoint:
GET /api/projects/{project_id}/file_download_batch_exports/{run_id}/download/{part}/part can be either:
files array returned by file-download-batch-exports-retrieveIf there is only one file, this also works without part:
GET /api/projects/{project_id}/file_download_batch_exports/{run_id}/download/Let the HTTP client follow the redirect, or inspect the Location header if you need the temporary signed URL. Use the same PostHog authentication context as other API calls.
Treat the result as a file download, not a chat response. Parquet is binary and must be written as bytes. JSONLines may still be large; save it to a file rather than pasting the contents unless the user explicitly asks for a tiny sample.
Use a filename that includes the model, run ID, and part identifier when possible, for example:
posthog-events-<run_id>-<part>.jsonl.gz
posthog-persons-<run_id>-<part>.parquetRunning after completion while file records are being created. Poll again instead of failing immediately.files; do not assume part 0 is enough.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.