mixpanel-automation

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to connect to an external MCP server at https://rube.app/mcp. This directs all tool requests and data processing to a third-party service endpoint not recognized as a standard trusted vendor.\n- [COMMAND_EXECUTION]: Includes the MIXPANEL_JQL_QUERY tool, which allows the agent to generate and execute custom JavaScript code (JQL) on the Mixpanel platform for advanced data processing.\n- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external data from Mixpanel.\n
  • Ingestion points: User profiles and event properties retrieved via MIXPANEL_QUERY_PROFILES and MIXPANEL_AGGREGATE_EVENT_COUNTS.\n
  • Boundary markers: Absent. The instructions do not provide delimiters or warnings to treat the retrieved data as untrusted.\n
  • Capability inventory: The skill has the capability to update profile data (MIXPANEL_PROFILE_BATCH_UPDATE) and execute remote scripts (MIXPANEL_JQL_QUERY).\n
  • Sanitization: Absent. There is no evidence of data validation or filtering before the retrieved information is used in subsequent tool calls or agent logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 04:39 PM
Security Audit — agent-trust-hub — mixpanel-automation