sap-rpt1
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill follows best practices for data governance and local processing.
- [PROMPT_INJECTION]: No malicious behavior overrides or safety bypass instructions were detected in the skill metadata or instructional content.
- [DATA_EXFILTRATION]: No unauthorized data access or network transmission patterns were found. The included scripts implement scanners to detect and prevent the accidental inclusion of sensitive information like IBANs, bank details, or personal data in datasets.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets or API keys are present. The skill correctly manages Hugging Face authentication by checking environment variables or local caches rather than hardcoding tokens.
- [EXTERNAL_DOWNLOADS]: The skill documents its dependency on the SAP-RPT-1-OSS library from SAP's official GitHub repository as a manual, approval-gated setup step, following standard development practices.
- [COMMAND_EXECUTION]: Local shell usage is restricted to legitimate data processing and inference tasks using the provided Python scripts, with clear documentation regarding non-administrator execution.
Audit Metadata