sap-datasphere
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core documentation and official SAP CLI usage fit the stated SAP Datasphere purpose, and the SFTP mentions are benign product references. The main risk is the third-party MCP server run via npx and given SAP OAuth credentials, plus its access to mutating tenant operations; this makes the skill materially riskier than a documentation-only or SAP-only workflow skill.
Confidence: 89%Severity: 82%
Audit Metadata