cargo-cli-analytics
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the
@cargo-ai/clitool to perform analytics tasks. The commands provided, such ascargo-ai orchestration run get-metricsandcargo-ai segmentation segment download, are standard for the platform's data management features. - [EXTERNAL_DOWNLOADS]: The skill instructions specify installing the
@cargo-ai/clipackage from npm. This package is the official tool from the vendor (getcargo) and is necessary for the skill's functionality. - [PROMPT_INJECTION]: The skill provides capability to download workflow and segment data, which represents an ingestion surface for indirect prompt injection. However, this is inherent to the skill's analytics purpose and no malicious patterns or unsafe interpolations were found in the provided files.
Audit Metadata