sap-btp-integration-suite
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill functions primarily as a documentation resource and template library for enterprise integration on SAP BTP.
- [COMMAND_EXECUTION]: The skill documents the use of standard CLI tools such as the Cloud Foundry CLI (
cf) and Kubernetes CLI (kubectl) for legitimate operations like viewing logs and managing cluster resources. These are provided as educational examples and do not constitute malicious command execution. - [EXTERNAL_DOWNLOADS]: The skill references official documentation and GitHub repositories hosted by SAP (
sap.comandgithub.com/SAP-docs). These are well-known and trusted sources for the technology described, and the references are documented neutrally for informational purposes. - [CREDENTIALS_UNSAFE]: While the skill provides templates and documentation for handling security material (credentials, certificates, and API keys) within the SAP Integration Suite environment, no actual secrets are hardcoded. It correctly teaches best practices such as using credential artifacts and the
SecureStoreServicerather than hardcoding sensitive data. - [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by providing instructions on how to process external data (XML, JSON, EDI) through integration flows and scripts. However, it includes best practices for input validation and sanitization within those contexts, and the risk to the agent itself is minimal given its primary role as a documentation provider.
Audit Metadata