sap-api-policy
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong security boundaries by explicitly instructing the agent to never request or accept passwords, API keys, or other sensitive credentials, directing the user to use aggregate counts and redacted summaries instead.- [SAFE]: Data ingestion from external sources (SAP API Hub, SAP Notes, SAP Docs) includes explicit instructions for the agent to watch for and report potential prompt injection attempts in tool outputs.- [SAFE]: Access to live systems via the ARC-1 MCP server is strictly limited to read-only and metadata-only operations (e.g., checking release states and dependencies), with mutating operations and business data previewing explicitly disabled by instruction.- [SAFE]: All external URLs and dependencies point to official SAP domains or well-known technical documentation portals, aligning with secure sourcing practices.
Audit Metadata