sap-dependency-security
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a comprehensive security orchestration framework for SAP projects, focusing on supply chain protection and dependency hardening.
- [EXTERNAL_DOWNLOADS]: Instructs users to install security tools such as Socket CLI, npq, and sfw from official registries to perform proactive auditing.
- [COMMAND_EXECUTION]: Includes a utility script (generate-dependency-upgrades.sh) to automate the creation of security-hardened configuration files using local templates.
- [SAFE]: Implements a strict policy for SAP Model Context Protocol (MCP) servers, requiring exact version pins and commit-based source installs (e.g., for the vendor-maintained SAP Analytics Cloud MCP) to prevent dependency confusion and malicious upgrades.
Audit Metadata