sap-btp-cloud-logging

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill details the use of cf, btp, and kubectl CLI tools to manage SAP BTP service instances and bindings, which are standard operations for the target environment.
  • [EXTERNAL_DOWNLOADS]: The skill references official SAP packages and documentation from trusted sources like GitHub, SAP Help Portal, and established projects like OpenTelemetry and OpenSearch.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface where the agent processes external application logs and traces.
  • Ingestion points: Log data is processed from Cloud Foundry, Kyma, OTLP endpoints, and JSON APIs as described in SKILL.md and reference files.
  • Boundary markers: A Data Protection Notice in SKILL.md warns against transmitting sensitive data.
  • Capability inventory: The agent is provided with instructions for executing cf, btp, and kubectl commands, and using curl for API interactions.
  • Sanitization: The skill relies on user adherence to data protection guidelines rather than automated content sanitization within the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:22 AM
Security Audit — agent-trust-hub — sap-btp-cloud-logging