sap-dependency-security

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive guidance and automation for security hardening of dependency trees and SAP MCP server configurations. It promotes industry-standard security tools and practices.
  • [EXTERNAL_DOWNLOADS]: The skill references a repository at github.com/secondsky/sap_analytics_cloud_mcp. As a vendor-owned resource used for source-based installation of a specific component, it is documented with mandatory commit SHA pinning to ensure integrity.
  • [COMMAND_EXECUTION]: The provided utility script generate-dependency-upgrades.sh is a local bash script used exclusively for generating configuration files from included templates. It performs no network operations or unsafe shell execution.
  • [PROMPT_INJECTION]: A review of the instructional content and templates found no attempts to bypass safety filters, extract system prompts, or override agent constraints.
  • [DATA_EXFILTRATION]: No evidence of hardcoded credentials, unauthorized file access, or attempts to exfiltrate sensitive data. The skill specifically instructs users to manage secrets via environment variables or specialized tools like 1Password CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:49 AM
Security Audit — agent-trust-hub — sap-dependency-security