sap-btp-build-work-zone-advanced

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation and configuration templates for the SAP Build Work Zone platform. All analyzed files focus on legitimate enterprise integration patterns, administration console guides, and UI Integration Card development.
  • [SAFE]: All external references and documentation links point to official SAP domains (e.g., help.sap.com, api.sap.com, sapjam.com, cai.tools.sap) or official SAP documentation repositories on GitHub. These are recognized as trusted services for the context of this skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a platform capable of ingesting untrusted data through OData APIs, external storage (Google Drive, SharePoint), and user-generated collaborative content (wikis, blogs).
  • Ingestion points: Data enters the system via OData business record integrations and external content providers as described in SKILL.md and references/api-reference.md.
  • Boundary markers: The skill references platform-level security features such as 'Compliance Monitor' and 'Profanity Monitor' in references/security.md to flag potentially malicious or non-compliant content.
  • Capability inventory: The skill enables management of user provisioning (SCIM), system-level event tracking (Webhooks), and business data display via UI Integration Cards as documented in references/ui-integration-cards.md.
  • Sanitization: The documentation describes administrative oversight tools, including moderation rules and scanning filters mentioned in references/administration.md and references/auditing.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:16 AM
Security Audit — agent-trust-hub — sap-btp-build-work-zone-advanced