sap-clean-core-atc

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes platform-native tools such as SAPRead, SAPSearch, SAPContext, and SAPDiagnose to perform code analysis and diagnostics. These tools are used as intended for auditing and do not exhibit suspicious behavior or unexpected command execution.
  • [EXTERNAL_DOWNLOADS]: The skill references the SAP/abap-atc-cr-cv-s4hc GitHub repository as an official source for machine-readable release state lists. This reference targets a well-known technology provider and is used purely for data classification purposes.
  • [SAFE]: All identified external tools and resources, including the mcp-sap-docs service, are consistent with the vendor's (arc-mcp) infrastructure and the specific domain of SAP auditing.
  • [SAFE]: Surface for indirect prompt injection exists in SKILL.md where custom ABAP source code is read for analysis.
  • Ingestion points: Custom ABAP source code is read via SAPRead in Step 2a.
  • Boundary markers: Not explicitly specified in the prompt instructions.
  • Capability inventory: Tools include SAPRead, SAPSearch, SAPContext, SAPDiagnose, and sap_get_object_details.
  • Sanitization: No specific sanitization of the source code is performed before classification logic is applied. Despite the ingestion of untrusted source code, the skill uses the data exclusively for categorical classification and report generation, which prevents the content from influencing the agent's operational instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 08:00 AM
Security Audit — agent-trust-hub — sap-clean-core-atc