cargo-cli-analytics

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the @cargo-ai/cli tool to perform analytics tasks. The commands provided, such as cargo-ai orchestration run get-metrics and cargo-ai segmentation segment download, are standard for the platform's data management features.
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify installing the @cargo-ai/cli package from npm. This package is the official tool from the vendor (getcargo) and is necessary for the skill's functionality.
  • [PROMPT_INJECTION]: The skill provides capability to download workflow and segment data, which represents an ingestion surface for indirect prompt injection. However, this is inherent to the skill's analytics purpose and no malicious patterns or unsafe interpolations were found in the provided files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 05:20 PM