cap-mcp-server

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing official SAP development tools, specifically @sap/cds-mcp, @sap/ui5-mcp-server, and @sap/fiori-mcp-server via npm. These are standard packages from a well-known enterprise software provider.
  • [COMMAND_EXECUTION]: The documentation includes configuration snippets that use npx to launch the MCP servers. This is the standard execution method for the Model Context Protocol and is scoped to the project's development dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The cap-model-explorer agent uses tools like search_model and search_docs to ingest project metadata and official documentation. This is a standard functional pattern for this type of agent, used to provide context-aware assistance rather than executing untrusted instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:54 AM
Security Audit — agent-trust-hub — cap-mcp-server