sap-dependency-security
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive guidance and automation for security hardening of dependency trees and SAP MCP server configurations. It promotes industry-standard security tools and practices.
- [EXTERNAL_DOWNLOADS]: The skill references a repository at
github.com/secondsky/sap_analytics_cloud_mcp. As a vendor-owned resource used for source-based installation of a specific component, it is documented with mandatory commit SHA pinning to ensure integrity. - [COMMAND_EXECUTION]: The provided utility script
generate-dependency-upgrades.shis a local bash script used exclusively for generating configuration files from included templates. It performs no network operations or unsafe shell execution. - [PROMPT_INJECTION]: A review of the instructional content and templates found no attempts to bypass safety filters, extract system prompts, or override agent constraints.
- [DATA_EXFILTRATION]: No evidence of hardcoded credentials, unauthorized file access, or attempts to exfiltrate sensitive data. The skill specifically instructs users to manage secrets via environment variables or specialized tools like 1Password CLI.
Audit Metadata