sap-sac-scripting

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides setup instructions for a Model Context Protocol (MCP) server hosted on the author's GitHub repository. It recommends cloning the source from https://github.com/secondsky/sap_analytics_cloud_mcp to enable extended REST API capabilities for the agent.
  • [REMOTE_CODE_EXECUTION]: Instructions are provided for the user to clone, build, and configure an external MCP server. The skill follows security best practices by instructing the user to check out a specific commit hash (2020235505d98111c2889598ab2217c1619b6943) and to use the --ignore-scripts flag during the Node.js package installation to prevent the execution of potentially malicious lifecycle scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:16 AM
Security Audit — agent-trust-hub — sap-sac-scripting