sap-migration-dossier

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates an attack surface for indirect prompt injection by processing external data from SAP extracts. These extracts are ingested and used to generate migration reports without explicit isolation or sanitization mechanisms.
  • Ingestion points: SKILL.md (specifically instructions to parse local extracts and read objects via SAPRead).
  • Boundary markers: The instructions do not define delimiters or markers to isolate ingested content from the agent's internal reasoning or report templates.
  • Capability inventory: SKILL.md (includes the ability to write various dossier artifacts including .html, .jsonl, and .csv files to the local file system).
  • Sanitization: There are no requirements or instructions to sanitize or escape data extracted from SAP systems or local files before it is included in the output dossiers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 06:22 PM
Security Audit — agent-trust-hub — sap-migration-dossier