sap-migration-dossier

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the SAP Docs MCP to search and fetch documentation from SAP's official help and discovery services. These operations target well-known service domains for legitimate architectural guidance and do not contribute to verdict escalation.
  • [COMMAND_EXECUTION]: The skill interacts with the SAP environment using defined tools such as SAPRead, SAPSearch, SAPDiagnose, and SAPQuery. The instructions include explicit safety constraints to prevent unauthorized system modifications or unscoped data extraction.
  • [DATA_EXFILTRATION]: The skill processes SAP system objects and user-provided local extracts to generate migration reports. There is no evidence of unauthorized access to sensitive local environment files (like .ssh or .aws) or exfiltration to untrusted external domains.
  • [PROMPT_INJECTION]: The skill instructions provide structured guidance for the agent's behavior without attempting to bypass safety filters or override system-level constraints. It includes clear boundaries for AI-generated vs. human-reviewed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 01:50 PM
Security Audit — agent-trust-hub — sap-migration-dossier