Skip to content
Back to skills

Auditing Experiments Flags

ASecurity

Audit PostHog experiments and feature flags for configuration issues, staleness, and best-practice violations. Read when the user asks to audit, health-check, or review experiments or feature flags, check flag hygiene, or verify experiment setup.

  • 40,048 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 1, 2026
datagosql

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 20, 2026

npx -y skills add PostHog/posthog --skill auditing-experiments-flags --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Auditing Experiments Flags?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Auditing Experiments Flags
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/posthog-auditing-experiments-flags-posthog/badge)](https://www.skillsdirectory.com/skills/posthog-auditing-experiments-flags-posthog)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: auditing-experiments-flags
description: 'Audit PostHog experiments and feature flags for configuration issues, staleness, and best-practice violations. Read when the user asks to audit, health-check, or review experiments or feature flags, check flag hygiene, or verify experiment setup.'
---

# Auditing experiments and feature flags

This skill teaches you how to run configuration audits on experiments and feature flags.
All checks use the experiment and feature flag read tools (`experiment-get`, `experiment-list`, `feature-flag-get-definition`, `feature-flag-get-all`) β€” no SQL queries are needed for Phase 1 checks.

## Usage modes

### Quick check (single entity)

When the user asks about a specific experiment or flag:

1. Fetch the entity via `experiment-get` (experiment ID) or `feature-flag-get-definition` (numeric flag ID).
2. Apply the relevant checks from [experiment checks](./references/experiment-checks.md) or [flag checks](./references/flag-checks.md).
3. Report findings inline as markdown, grouped by severity (CRITICAL first, then WARNING, then INFO).
4. Include entity links as `[Experiment: name](/experiments/id)` or `[Flag: key](/feature_flags/id)`.

### Scoped audit (one domain)

When the user asks to audit all experiments or all flags:

1. Bulk-fetch via `experiment-list` or `feature-flag-get-all`.
2. Run all checks for that domain against each entity.
3. Group findings by severity, then by entity.
4. Report as inline markdown.

### Full audit (comprehensive)

When the user asks for a comprehensive audit of both experiments and flags:

1. Fetch all experiments via `experiment-list` and all flags via `feature-flag-get-all`.
2. Run all experiment checks and all flag checks.
3. Apply [recurring patterns](./references/synthesis-patterns.md) to identify patterns across multiple findings.
4. If there are more than 5 entities with findings, write them to a notebook for easier navigation. Otherwise report inline. Create the notebook from the project's own notebook tools. Run `search notebooks?-` to load them and read the titles.

## Output format

For each finding, include:

- **Severity badge**: `πŸ”΄ CRITICAL`, `🟑 WARNING`, or `πŸ”΅ INFO`
- **Check name**: Which check produced this finding
- **Entity link**: Markdown link to the entity
- **What's wrong**: One-sentence description
- **Action**: What to do about it (see [remediation actions](./references/remediation-actions.md))

Example:

> 🟑 **WARNING** β€” Flag integration Β· [Experiment: checkout-redesign](/experiments/42)
> The linked feature flag is inactive (paused). Traffic is not being split.
> **Action**: Re-enable the flag or end the experiment.

## Handling unavailable data

Some checks require activity logs (`feature-flags-activity-retrieve` for flags), which may not be available in every session.
If activity log data is unavailable:

- Skip `checkActivityHistory` (experiment check) entirely.
- Skip the "toggle instability" and "never activated" sub-checks in flag lifecycle checks.
- In your report, note which checks were skipped and why:
  > _Skipped: Activity history checks (activity logs not available via current tools)_

## Partial failures

If a fetch call fails for some entities:

- Continue with the entities you could fetch.
- Report which entities could not be assessed and why.
- Do not silently omit entities from the audit.

## Reference files

- [Experiment checks](./references/experiment-checks.md) β€” experiment configuration checks
- [Flag checks](./references/flag-checks.md) β€” feature flag checks
- [Finding types](./references/finding-taxonomy.md) β€” severity and category definitions
- [Recurring patterns](./references/synthesis-patterns.md) β€” patterns across multiple findings
- [Remediation actions](./references/remediation-actions.md) β€” what to do about each finding

Files in this skill

  • SKILL.md3.7 KB
  • references/experiment-checks.md8.8 KB
  • references/finding-taxonomy.md2.6 KB
  • references/flag-checks.md.j25.5 KB
  • references/remediation-actions.md5.2 KB
  • references/synthesis-patterns.md1.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…