security-auth

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents best practices for SAP CAP security, including service-level and entity-level access control using standard @requires and @restrict annotations. The examples provided are consistent with official SAP documentation.
  • [SAFE]: The security-reviewer agent in agents/security-reviewer.md provides a structured workflow for auditing CDS and JSON configurations. While it processes user-provided code (a surface for indirect prompt injection), the agent lacks capabilities to execute code or write to the filesystem, which mitigates security risks.
  • [SAFE]: All external references point to official SAP documentation domains (cap.cloud.sap), which are recognized as well-known and trusted services for this skill's context. No unauthorized network operations or data exfiltration attempts were detected.
  • [SAFE]: Local development mock users and service bindings described in the documentation follow standard framework patterns for testing and do not involve hardcoded credentials for production environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 09:05 PM
Security Audit — agent-trust-hub — security-auth