explain-abap-code

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes specialized tools such as SAPSearch, SAPRead, SAPContext, and SAPDiagnose to interact with a connected SAP backend. These tools are used as intended to retrieve ABAP source code, metadata, and diagnostic information for the purpose of analysis and explanation.
  • [EXTERNAL_DOWNLOADS]: The skill performs lookups using sap_notes_search and general documentation searches. These operations target well-known and official SAP resources to provide the user with authoritative context and best practices regarding the code being analyzed.
  • [PROMPT_INJECTION]: The skill processes external source code and documentation retrieved from the SAP system. While this represents a surface for indirect prompt injection (where instructions could be hidden in code comments), the skill's design focuses on documentation and explanation, which inherently limits the scope of any potential unauthorized actions triggered by such content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 11:09 AM
Security Audit — agent-trust-hub — explain-abap-code