segment-automation

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-controlled data for analytics tracking, creating a surface for indirect prompt injection.
  • Ingestion points: User data enters via the userId, anonymousId, event, properties, and traits parameters in tools like SEGMENT_TRACK, SEGMENT_IDENTIFY, and SEGMENT_BATCH defined in SKILL.md.
  • Boundary markers: Absent. No delimiters or clear isolation markers are used to distinguish user data from agent instructions.
  • Capability inventory: The skill enables network operations through Segment's API tools to send customer data to external destinations.
  • Sanitization: Absent. The skill instructions do not specify any validation or filtering for data passed to the Segment toolkit.
  • [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server endpoint (https://rube.app/mcp) for its core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 09:33 AM