"The use of the "Carbon-Emissions-Scope-2" header field does not introduce any new security risks" - I think this is just incorrect.
Knowing how much a single request is producing carbon emissions tells you immediately which operations are going to be costly to a business.
You could enumerate a site's tree, find the most taxing operation, and then hammer it, because carbon-emission is short-hand for cost.