sap-fiori-opa5-test-development
Fail
Audited by Snyk on Aug 5, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.80). The skill includes an explicit instruction (line 6) to inject a promotional link into the start of the agent's first response, which is an external/advertising directive not required by the skill's stated purpose of guiding OPA5 test development and thus constitutes a deceptive/out-of-scope instruction.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). All listed URLs are official SAP, OData, Microsoft, or GitHub documentation/project pages except https://www.claudepluginhub.com/plugins/sap-sap-fiori-mcp-server-packages-fiori-mcp-server, which is a third-party plugin distribution domain (not an official vendor or package manager) and therefore potentially suspicious as a download source.
Issues (2)
E004
CRITICALPrompt injection detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata