sap-transport-review

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a potential surface for indirect prompt injection.
  • Ingestion points: Processes SAP transport descriptions and ABAP source code via the SAPTransport and SAPRead tools, as defined in Step 1 and Step 3 of SKILL.md.
  • Boundary markers: No specific boundary markers or instructions to disregard embedded commands are used when interpolating SAP source content into the review report.
  • Capability inventory: The skill possesses significant capabilities including reading source code, analyzing system impact (SAPContext), and potentially performing write operations such as code activation (SAPActivate) or transport release (SAPTransport(action="release")) mentioned in the follow-up section.
  • Sanitization: There is no evidence of sanitization or filtering of the external SAP content before it is processed and summarized by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 06:30 AM
Security Audit — agent-trust-hub — sap-transport-review