sap-btp-integration-suite

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official SAP documentation and repositories hosted on GitHub (github.com/SAP-docs) and the SAP Help Portal. These are well-known technology service providers and the references are used for informational purposes and configuration templates.- [COMMAND_EXECUTION]: Instructions in iflow-package-authoring.md include standard shell commands like zip for packaging integration artifacts. These are legitimate instructional steps for the intended enterprise integration use case and do not involve unsanitized user input.- [CREDENTIALS_UNSAFE]: The skill utilizes externalized parameters and placeholders (e.g., {{SFTP_CREDENTIAL_ALIAS}}, {{SFTP_HOST}}) to manage sensitive configuration. This is a security best practice that prevents hardcoding credentials in integration artifacts.- [SAFE]: The Groovy script templates provided in scripting.md and groovy-script-template.groovy explicitly warn against insecure practices, such as logging credentials to headers or using the insecure Eval class.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:49 AM
Security Audit — agent-trust-hub — sap-btp-integration-suite