security-auth
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents best practices for SAP CAP security, including service-level and entity-level access control using standard @requires and @restrict annotations. The examples provided are consistent with official SAP documentation.
- [SAFE]: The
security-revieweragent inagents/security-reviewer.mdprovides a structured workflow for auditing CDS and JSON configurations. While it processes user-provided code (a surface for indirect prompt injection), the agent lacks capabilities to execute code or write to the filesystem, which mitigates security risks. - [SAFE]: All external references point to official SAP documentation domains (
cap.cloud.sap), which are recognized as well-known and trusted services for this skill's context. No unauthorized network operations or data exfiltration attempts were detected. - [SAFE]: Local development mock users and service bindings described in the documentation follow standard framework patterns for testing and do not involve hardcoded credentials for production environments.
Audit Metadata