sap-sac-test-automation

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the use of chrome-devtools-mcp via npx. This is documented as a discovery tool for SAP Analytics Cloud. The instructions provide comprehensive guidance for enterprise environments, such as using internal registries, pinning versions, and disabling telemetry/update checks to maintain a secure supply chain.
  • [COMMAND_EXECUTION]: Provides legitimate PowerShell and Bash scripts for environment capability checks (e.g., verifying Node.js, npm, or browser installation) and for launching the Microsoft Edge browser with specific remote debugging flags. These operations are functional requirements of the automation framework and are accompanied by explicit warnings to keep debugging ports bound only to the local interface (127.0.0.1).
  • [DATA_EXFILTRATION]: Includes robust defensive instructions regarding sensitive data. It explicitly forbids the storage of authentication states, cookies, or secrets in Git, and provides detailed policies for redacting network headers and identifiers when capturing discovery artifacts. It further restricts the use of external research tools like Firecrawl to public documentation only.
  • [PROMPT_INJECTION]: The skill follows a 'discovery proposes, humans approve' model, which serves as a critical safety boundary against potentially malicious instructions embedded in the analyzed dashboard content. It provides templates that require manual human completion and verification before integration into CI/CD pipelines.
  • [SAFE]: The skill demonstrates high security maturity by addressing restricted Windows environments, enterprise browser policies (like RemoteDebuggingAllowed), and the need for dedicated automation profiles to prevent the leakage of personal user data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 09:26 AM
Security Audit — agent-trust-hub — sap-sac-test-automation