mixpanel-automation
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated Mixpanel purpose is mostly aligned with the capabilities, but the trust and data-flow model are weak. The skill routes Mixpanel auth and data through a third-party hosted MCP service, uses outdated/discontinued Rube setup, and gives misleading setup claims versus current official Composio docs. This is not confirmed malware, but it is a medium-high risk integration pattern for an AI skill.
Confidence: 87%Severity: 74%
Audit Metadata