instrument-feature-flags — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited instrument-feature-flags (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to add PostHog feature flags that gate new or changed functionality. Use it after implementing features or reviewing PRs to ensure safe rollouts with feature flag controls. If PostHog is not yet installed, this skill also covers initial SDK setup. Supports any platform or language.
Supported platforms: React, Next.js, React Native, Web (JavaScript), Node.js, Python, PHP, Ruby, Go, Java, Rust, .NET, Elixir, Android, iOS, Flutter, and the REST API.
Follow these steps IN ORDER:
STEP 1: Analyze the codebase and detect the platform. - Look for dependency files (package.json, pubspec.yaml, Podfile, Package.swift, requirements.txt, go.mod, Gemfile, composer.json, mix.exs, etc.) to determine the language and framework. - Look for lockfiles (pnpm-lock.yaml, package-lock.json, yarn.lock, bun.lockb, go.sum, pubspec.lock, Podfile.lock, Package.resolved, mix.lock) to determine the package manager.
STEP 2: Research instrumentation. (Skip if PostHog is already set up.) 2.1. Find the reference file below that matches the detected platform — it is the source of truth for SDK initialization, flag evaluation methods, and framework-specific patterns. Read it now. 2.2. If no reference matches, fall back to your general knowledge and web search. Use posthog.com/docs as the primary search source.
STEP 3: Create or find the feature flag.
STEP 4: Plan release conditions.
STEP 5: Instrument the feature.
STEP 6: Set up environment variables.
.env, .env.local, or framework-specific env files). If valid values already exist, skip this step.projects-get tool to retrieve the project's api_token. If multiple projects are returned, ask the user which project to use. If the MCP server is not connected or not authenticated, ask the user for their PostHog project API key instead.https://us.i.posthog.com for US Cloud or https://eu.i.posthog.com for EU Cloud.references/react.md - React feature flags installation - docsreferences/react-native.md - React native feature flags installation - docsreferences/web.md - Web feature flags installation - docsreferences/nodejs.md - Node.js feature flags installation - docsreferences/python.md - Python feature flags installation - docsreferences/django.md - Django - docsreferences/flask.md - Flask - docsreferences/php.md - Php feature flags installation - docsreferences/laravel.md - Laravel - docsreferences/ruby.md - Ruby feature flags installation - docsreferences/ruby-on-rails.md - Ruby on rails - docsreferences/go.md - Go feature flags installation - docsreferences/java.md - Java feature flags installation - docsreferences/rust.md - Rust feature flags installation - docsreferences/dotnet.md - .net feature flags installation - docsreferences/dotnet.md - .net - docsreferences/elixir.md - Elixir feature flags installation - docsreferences/android.md - Android feature flags installation - docsreferences/ios.md - Ios feature flags installation - docsreferences/usage.md - Ios SDK usage - docsreferences/flutter.md - Flutter feature flags installation - docsreferences/api.md - API feature flags installation - docsreferences/next-js.md - Next.js - docsreferences/adding-feature-flag-code.md - Adding feature flag code - docsreferences/best-practices.md - Best practices for production-ready flags - docsEach platform reference contains SDK-specific installation, flag evaluation, and code examples. Find the one matching the user's stack. If unlisted, use the API reference as a fallback.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.