PostHogBLOCK
Official PostHog MCP Server 🦔
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The MCP server has been moved into the PostHog Monorepo - you can find it here.
Documentation: https://posthog.com/docs/model-context-protocol
Use the MCP Server
Quick install
You can install the MCP server automatically into Cursor, Claude, Claude Code, VS Code and Zed by running the following command:
npx @posthog/wizard@latest mcp add
1aeb7559b341OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add agent-toolkit --env OPENAI_API_KEY=${OPENAI_API_KEY} --env POSTHOG_PERSONAL_API_KEY=${POSTHOG_PERSONAL_API_KEY} --env TEST_POSTHOG_PERSONAL_API_KEY=${TEST_POSTHOG_PERSONAL_API_KEY} -- npx -y @posthog/[email protected]{
"mcpServers": {
"agent-toolkit": {
"command": "npx",
"args": [
"-y",
"@posthog/[email protected]"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"POSTHOG_PERSONAL_API_KEY": "${POSTHOG_PERSONAL_API_KEY}",
"TEST_POSTHOG_PERSONAL_API_KEY": "${TEST_POSTHOG_PERSONAL_API_KEY}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
button_click | read | Button click rate |
engagement | read | User engagement ratio |
purchase | read | Average revenue |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(query: string): Promise<D1ExecResult>;
.release-please-config.json
.release-please-manifest.json
.env.test.example
const outputPath = path.join(__dirname, "../../schema/tool-inputs.json");
import toolDefinitionsJson from "../../../schema/tool-definitions.json";
atob(data: string): string;
declare function atob(data: string): string;
@ai-sdk/openai, @posthog/agent-toolkit, ai, dotenv, zod, @types/node, tsx, typescript
@langchain/core, @langchain/openai, @posthog/agent-toolkit, dotenv, langchain, zod, @types/node, tsx
husky, tsx
@modelcontextprotocol/sdk, agents, ai, posthog-node, uuid, zod, @langchain/core, @langchain/openai
Gates applied: no_behavioural_pass.
1aeb7559b341full audit observations/trust-audit/mcp-server/posthog__posthog-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1aeb7559b341 | BLOCK | D | 69 | first audit |
Questions
What is the PostHog MCP server?
Official PostHog MCP Server 🦔
What tools does PostHog expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is PostHog safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does PostHog need?
It reads OPENAI_API_KEY, POSTHOG_PERSONAL_API_KEY and TEST_POSTHOG_PERSONAL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does PostHog run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @posthog/agent-toolkit at 0.2.2.
How current is this page?
The grade is for one exact copy of the source (1aeb7559b341), read on 2026-10-07. The repository is watched and re-audited when it changes.