mixpanel-automation
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the user to connect to an external MCP server at https://rube.app/mcp. This directs all tool requests and data processing to a third-party service endpoint not recognized as a standard trusted vendor.\n- [COMMAND_EXECUTION]: Includes the MIXPANEL_JQL_QUERY tool, which allows the agent to generate and execute custom JavaScript code (JQL) on the Mixpanel platform for advanced data processing.\n- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external data from Mixpanel.\n
- Ingestion points: User profiles and event properties retrieved via MIXPANEL_QUERY_PROFILES and MIXPANEL_AGGREGATE_EVENT_COUNTS.\n
- Boundary markers: Absent. The instructions do not provide delimiters or warnings to treat the retrieved data as untrusted.\n
- Capability inventory: The skill has the capability to update profile data (MIXPANEL_PROFILE_BATCH_UPDATE) and execute remote scripts (MIXPANEL_JQL_QUERY).\n
- Sanitization: Absent. There is no evidence of data validation or filtering before the retrieved information is used in subsequent tool calls or agent logic.
Audit Metadata