amplitude-automation
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for Indirect Prompt Injection (Category 8).
- Ingestion points: Data retrieved from Amplitude via
AMPLITUDE_GET_USER_ACTIVITY,AMPLITUDE_FIND_USER, andAMPLITUDE_LIST_COHORTSenters the agent context. - Boundary markers: None identified in the prompt templates to distinguish between instructions and data.
- Capability inventory: The skill is restricted to Amplitude API operations (events, identification, cohorts). It does not have access to the local file system, shell execution, or arbitrary network requests outside the MCP framework.
- Sanitization: No explicit validation or sanitization of retrieved analytics data is implemented before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill requires a connection to a remote MCP server at
https://rube.app/mcp. This is a core infrastructure requirement for the Rube/Composio ecosystem and is considered a well-known service for this skill's functionality.
Audit Metadata