mixpanel-automation
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard documentation and workflow guidance for a legitimate analytics integration without any detected malicious patterns.
- [COMMAND_EXECUTION]: The tool
MIXPANEL_JQL_QUERYaccepts ascriptparameter for executing Mixpanel's JavaScript Query Language. This is a standard functional requirement of the Mixpanel API for performing complex data analysis. - [EXTERNAL_DOWNLOADS]: The skill utilizes the Rube MCP server endpoint at
https://rube.app/mcp. This is the infrastructure provider for the skill's capabilities and is explicitly documented as a prerequisite for setup. - [PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection as it ingests untrusted data from Mixpanel (e.g., user profile properties or event names) via tools like
MIXPANEL_QUERY_PROFILES. While no specific boundary markers are mandated in the instructions, this risk is inherent to data-processing skills and is consistent with its primary analytics purpose.
Audit Metadata