mixpanel-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard documentation and workflow guidance for a legitimate analytics integration without any detected malicious patterns.
  • [COMMAND_EXECUTION]: The tool MIXPANEL_JQL_QUERY accepts a script parameter for executing Mixpanel's JavaScript Query Language. This is a standard functional requirement of the Mixpanel API for performing complex data analysis.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the Rube MCP server endpoint at https://rube.app/mcp. This is the infrastructure provider for the skill's capabilities and is explicitly documented as a prerequisite for setup.
  • [PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection as it ingests untrusted data from Mixpanel (e.g., user profile properties or event names) via tools like MIXPANEL_QUERY_PROFILES. While no specific boundary markers are mandated in the instructions, this risk is inherent to data-processing skills and is consistent with its primary analytics purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — mixpanel-automation