sap-clean-core-atc
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes platform-native tools such as
SAPRead,SAPSearch,SAPContext, andSAPDiagnoseto perform code analysis and diagnostics. These tools are used as intended for auditing and do not exhibit suspicious behavior or unexpected command execution. - [EXTERNAL_DOWNLOADS]: The skill references the
SAP/abap-atc-cr-cv-s4hcGitHub repository as an official source for machine-readable release state lists. This reference targets a well-known technology provider and is used purely for data classification purposes. - [SAFE]: All identified external tools and resources, including the
mcp-sap-docsservice, are consistent with the vendor's (arc-mcp) infrastructure and the specific domain of SAP auditing. - [SAFE]: Surface for indirect prompt injection exists in
SKILL.mdwhere custom ABAP source code is read for analysis. - Ingestion points: Custom ABAP source code is read via
SAPReadin Step 2a. - Boundary markers: Not explicitly specified in the prompt instructions.
- Capability inventory: Tools include
SAPRead,SAPSearch,SAPContext,SAPDiagnose, andsap_get_object_details. - Sanitization: No specific sanitization of the source code is performed before classification logic is applied. Despite the ingestion of untrusted source code, the skill uses the data exclusively for categorical classification and report generation, which prevents the content from influencing the agent's operational instructions.
Audit Metadata