sap-migration-dossier

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill integrates with SAP-specific MCP tools (SAPRead, SAPSearch, SAPDiagnose, SAPDocs) to perform its intended audit functions and relies on standard platform capabilities for interacting with SAP environments.\n- [PROMPT_INJECTION]: The skill processes custom ABAP code and uploaded extracts, creating a surface for indirect prompt injection.\n
  • Ingestion points: ABAP source code read from SAP systems via SAPRead or imported from local file extracts.\n
  • Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within audited code content.\n
  • Capability inventory: The skill can perform system-wide searches and write complex reports to the local file system (docs/migration-dossiers/).\n
  • Sanitization: No specific sanitization or filtering of code comments or literal strings is performed before processing by the LLM.\n- [COMMAND_EXECUTION]: The skill mentions the use of SAPQuery for deep evidence gathering. However, it explicitly forbids its use unless the environment has enabled free SQL and the user has specifically requested deep evidence, which mitigates the risk of unauthorized or unintended database queries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:34 AM
Security Audit — agent-trust-hub — sap-migration-dossier