{"data":{"skill":{"slug":"sickn33-mixpanel-automation","name":"mixpanel-automation","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/mixpanel-automation","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"7598ebcd-658e-47b4-95f2-22b9fb6afe4c","skill_id":"b48d7dcb-eb3b-4d96-8108-6bca6faf7297","version":5,"content_hash":"v3:81e05e636292629114b76cbb3922fbe57672fc02:ab7a00c82e0f24003538bdaabfbbec93af5a031883c760abb66b88d9452fb58a:53183f3eb1b7ae4f85e0a0300d44b6a073cb0c1f58c6654926d79db4a1791ebc:736b696c6c732f7369636b6e33332f6d697870616e656c2d6175746f6d6174696f6e:7ed9e82c37c2251cfc730017c271c464","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The shell-execution and reconnaissance alerts are false positives caused by Markdown formatting and normal identifier resolution. The external MCP endpoint is a real low-risk trust boundary, while unconfirmed bulk profile changes present a medium operational risk.","remediation":[{"issue":"Bulk profile updates can change many user records without an explicit approval checkpoint.","severity":"medium","suggestion":"Require a scoped preview, affected-record count, operation summary, and explicit user confirmation before calling the batch update tool."},{"issue":"The workflow depends on an external Rube MCP endpoint and authentication flow.","severity":"low","suggestion":"Disclose the third-party data path, verify the endpoint, and obtain user approval before connecting or authenticating Mixpanel."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":91,"line_start":91},{"file":"SKILL.md","line_end":93,"line_start":93},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":105,"line_start":105},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":112,"line_start":112},{"file":"SKILL.md","line_end":113,"line_start":113},{"file":"SKILL.md","line_end":114,"line_start":114},{"file":"SKILL.md","line_end":123,"line_start":123},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":133,"line_start":133},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":141,"line_start":141},{"file":"SKILL.md","line_end":144,"line_start":144}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":21,"line_start":21}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Bulk Profile Updates Lack Explicit Confirmation","locations":[{"file":"SKILL.md","line_end":115,"line_start":96}],"confidence":0.94,"description":"The workflow permits batch profile mutations but does not require a preview, scope check, or user confirmation before applying changes.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The documented workflow explicitly includes batch profile updates and mutation operations. No confirmation or dry-run safeguard appears in the cited section."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":21,"line_start":21}],"confidence":0.96,"description":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The setup directs users to connect the external Rube MCP endpoint. This legitimate dependency creates a real network and third-party trust boundary."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":234,"audit_model":"codex","audited_at":"2026-08-04T14:24:34.077+00:00","created_at":"2026-08-05T01:15:11.804422+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Active Mixpanel connection via `RUBE_MANAGE_CONNECTIONS` with toolkit `mixpanel`","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Always call `RUBE_SEARCH_TOOLS` first to get current tool schemas","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `mixpanel`","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIXPANEL_GET_ALL_PROJECTS` - List projects to get project ID [Prerequisite]","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIXPANEL_AGGREGATE_EVENT_COUNTS` - Get event counts and aggregations [Required]","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `event`: Event name or array of event names to aggregate","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `from_date` / `to_date`: Date range in 'YYYY-MM-DD' format","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `unit`: Time granularity ('minute', 'hour', 'day', 'week', 'month')","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `type`: Aggregation type ('general', 'unique', 'average')","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `where`: Filter expression for event properties","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `where` filter uses Mixpanel expression syntax (e.g., `properties[\"country\"] == \"US\"`)","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIXPANEL_QUERY_SEGMENTATION` - Run segmentation analysis [Required]","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `event`: Event name to segment","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `from_date` / `to_date`: Date range in 'YYYY-MM-DD' format","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `on`: Property to segment by (e.g., `properties[\"country\"]`)","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `unit`: Time granularity","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `type`: Count type ('general', 'unique', 'average')","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `where`: Filter expression","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `limit`: Maximum number of segments to return","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The `on` parameter uses Mixpanel property expression syntax","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Property references must use `properties[\"prop_name\"]` format","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Segmentation on high-cardinality properties returns capped results; use `limit`","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIXPANEL_LIST_FUNNELS` - List saved funnels to find funnel ID [Prerequisite]","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIXPANEL_QUERY_FUNNEL` - Execute funnel analysis [Required]","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `funnel_id`: ID of the saved funnel to query","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `from_date` / `to_date`: Date range","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `unit`: Time granularity","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `where`: Filter expression","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `on`: Property to segment funnel by","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `length`: Conversion window in days","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `funnel_id` is required; resolve via LIST_FUNNELS first","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Conversion window (`length`) defaults vary; set explicitly for accuracy","category":"external_commands","line_end":93,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIXPANEL_QUERY_PROFILES` - Search and filter user profiles [Required]","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIXPANEL_PROFILE_BATCH_UPDATE` - Update multiple user profiles [Optional]","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `where`: Filter expression for profile properties (e.g., `properties[\"plan\"] == \"premium\"`)","category":"external_commands","line_end":105,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `output_properties`: Array of property names to include in results","category":"external_commands","line_end":106,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `page`: Page number for pagination","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `session_id`: Session ID for consistent pagination (from first response)","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For batch update: array of profile updates with `$distinct_id` and property operations","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Profile queries return paginated results; use `session_id` from first response for consistent pagi","category":"external_commands","line_end":112,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `where` uses Mixpanel expression syntax for profile properties","category":"external_commands","line_end":113,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- BATCH_UPDATE applies operations (`$set`, `$unset`, `$add`, `$append`) to profiles","category":"external_commands","line_end":114,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIXPANEL_COHORTS_LIST` - List all saved cohorts [Required]","category":"external_commands","line_end":123,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Response includes cohort `id`, `name`, `description`, `count`","category":"external_commands","line_end":127,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Cohorts can be used as filters in other queries via `where` expressions","category":"external_commands","line_end":133,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIXPANEL_JQL_QUERY` - Execute a custom JQL (JavaScript Query Language) query [Optional]","category":"external_commands","line_end":140,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIXPANEL_QUERY_INSIGHT` - Run a saved insight query [Optional]","category":"external_commands","line_end":141,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For JQL: `script` containing the JQL JavaScript code","category":"external_commands","line_end":144,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For Insight: `bookmark_id` of the saved insight","category":"external_commands","line_end":145,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `project_id`: Project context for the query","category":"external_commands","line_end":146,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Insight `bookmark_id` must reference an existing saved insight","category":"external_commands","line_end":151,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":163,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":166,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":170,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":174,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Used in `where` and `on` parameters:","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Property reference: `properties[\"property_name\"]`","category":"external_commands","line_end":176,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Equality: `properties[\"country\"] == \"US\"`","category":"external_commands","line_end":177,"severity":"medium","line_start":176},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Comparison: `properties[\"age\"] > 25`","category":"external_commands","line_end":178,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Boolean: `properties[\"is_premium\"] == true`","category":"external_commands","line_end":179,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Contains: `\"search_term\" in properties[\"name\"]`","category":"external_commands","line_end":180,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- AND/OR: `properties[\"country\"] == \"US\" and properties[\"plan\"] == \"pro\"`","category":"external_commands","line_end":185,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Profile queries: Use `page` number and `session_id` for consistent results","category":"external_commands","line_end":185,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Property references always use `properties[\"name\"]` format","category":"external_commands","line_end":197,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- String values must be quoted: `properties[\"status\"] == \"active\"`","category":"external_commands","line_end":198,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Numeric values are unquoted: `properties[\"count\"] > 10`","category":"external_commands","line_end":199,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Boolean values: `true` / `false` (lowercase)","category":"external_commands","line_end":199,"severity":"medium","line_start":199},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"blocker:SKILL.md:162:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"3. Extract project id","category":"blocker","line_end":163,"severity":"low","line_start":162},{"id":"blocker:SKILL.md:169:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"3. Extract funnel_id","category":"blocker","line_end":170,"severity":"low","line_start":169},{"id":"blocker:SKILL.md:225:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Query insight | MIXPANEL_QUERY_INSIGHT | bookmark_id |","category":"blocker","line_end":225,"severity":"low","line_start":225},{"id":"blocker:SKILL.md:130:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Cohorts are created and managed in Mixpanel UI; API provides read access","category":"blocker","line_end":131,"severity":"low","line_start":130}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The cited backticks delimit a Markdown workflow example. They are not Ruby backtick syntax and do not execute a local shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The cited backticks delimit a Markdown workflow example. They are not Ruby backtick syntax and do not execute a local shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The cited backticks delimit a Markdown workflow example. They are not Ruby backtick syntax and do not execute a local shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The cited backticks delimit a Markdown workflow example. They are not Ruby backtick syntax and do not execute a local shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"The cited backticks are Markdown inline-code formatting for a tool, parameter, URL, or expression. No Ruby or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:21:hardcoded-url","reason":"The setup directs users to connect the external Rube MCP endpoint. This legitimate dependency creates a real network and third-party trust boundary.","verdict":"confirmed","severity":"low","confidence":0.96},{"id":"blocker:SKILL.md:162:system-reconnaissance","reason":"The cited step reads an identifier from authorized Mixpanel results or lists a required identifier. It performs no operating-system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:169:system-reconnaissance","reason":"The cited step reads an identifier from authorized Mixpanel results or lists a required identifier. It performs no operating-system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:225:system-reconnaissance","reason":"The cited step reads an identifier from authorized Mixpanel results or lists a required identifier. It performs no operating-system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:130:network-reconnaissance","reason":"The text explains that cohort management occurs in Mixpanel while the API is read-only. It does not discover hosts, ports, services, or network topology.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Bulk Profile Updates Lack Explicit Confirmation","severity":"medium","locations":[{"file":"SKILL.md","line_end":115,"line_start":96}],"confidence":0.94,"description":"The workflow permits batch profile mutations but does not require a preview, scope check, or user confirmation before applying changes.","confidence_reasoning":"The documented workflow explicitly includes batch profile updates and mutation operations. No confirmation or dry-run safeguard appears in the cited section."}],"subject_marketplace_commit_sha":"81e05e636292629114b76cbb3922fbe57672fc02","subject_content_hash":"ab7a00c82e0f24003538bdaabfbbec93af5a031883c760abb66b88d9452fb58a","subject_tree_hash":"53183f3eb1b7ae4f85e0a0300d44b6a073cb0c1f58c6654926d79db4a1791ebc","subject_plugin_path":"skills/sickn33/mixpanel-automation","audit_payload_hash":"7ed9e82c37c2251cfc730017c271c464","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"81e05e636292629114b76cbb3922fbe57672fc02","contentHash":"ab7a00c82e0f24003538bdaabfbbec93af5a031883c760abb66b88d9452fb58a","treeHash":"53183f3eb1b7ae4f85e0a0300d44b6a073cb0c1f58c6654926d79db4a1791ebc","pluginPath":"skills/sickn33/mixpanel-automation","auditPayloadHash":"7ed9e82c37c2251cfc730017c271c464"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-mixpanel-automation/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}