sap-migration-dossier
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill integrates with SAP-specific MCP tools (SAPRead, SAPSearch, SAPDiagnose, SAPDocs) to perform its intended audit functions and relies on standard platform capabilities for interacting with SAP environments.\n- [PROMPT_INJECTION]: The skill processes custom ABAP code and uploaded extracts, creating a surface for indirect prompt injection.\n
- Ingestion points: ABAP source code read from SAP systems via
SAPReador imported from local file extracts.\n - Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within audited code content.\n
- Capability inventory: The skill can perform system-wide searches and write complex reports to the local file system (
docs/migration-dossiers/).\n - Sanitization: No specific sanitization or filtering of code comments or literal strings is performed before processing by the LLM.\n- [COMMAND_EXECUTION]: The skill mentions the use of
SAPQueryfor deep evidence gathering. However, it explicitly forbids its use unless the environment has enabled free SQL and the user has specifically requested deep evidence, which mitigates the risk of unauthorized or unintended database queries.
Audit Metadata