carto-composite-scoring
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's workflow templates (
composite-score-supervised.jsonandcomposite-score-unsupervised.json) reference external data sources located athttps://storage.googleapis.com/carto-workflows-examples/. These URLs point to a well-known service (Google Cloud Storage) and target a bucket explicitly designated for CARTO workflow examples. This is standard behavior for providing sample data to the user. - [COMMAND_EXECUTION]: The instructions and JSON files refer to CARTO platform-native components (e.g.,
native.spatialcompositesupervised,native.select). These are internal platform functions for spatial analysis and do not involve arbitrary shell command execution or unsafe system calls. - [DATA_EXFILTRATION]: No sensitive file access or unauthorized network operations were detected. The workflows process provided datasets within the scoped environment of a CARTO workflow.
Audit Metadata