amplitude-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for Indirect Prompt Injection (Category 8).
  • Ingestion points: Data retrieved from Amplitude via AMPLITUDE_GET_USER_ACTIVITY, AMPLITUDE_FIND_USER, and AMPLITUDE_LIST_COHORTS enters the agent context.
  • Boundary markers: None identified in the prompt templates to distinguish between instructions and data.
  • Capability inventory: The skill is restricted to Amplitude API operations (events, identification, cohorts). It does not have access to the local file system, shell execution, or arbitrary network requests outside the MCP framework.
  • Sanitization: No explicit validation or sanitization of retrieved analytics data is implemented before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill requires a connection to a remote MCP server at https://rube.app/mcp. This is a core infrastructure requirement for the Rube/Composio ecosystem and is considered a well-known service for this skill's functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — amplitude-automation