manage-zerocopy-sapbdc

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements management workflows for SAP BDC Zero-Copy Integration using official Snowflake SQL commands and system functions (e.g., SYSTEM$SAP_PUBLISH_DATA_PRODUCT). No malicious patterns, unauthorized data access, or obfuscation were detected.
  • [PROMPT_INJECTION]: The skill uses structured routing and trigger phrases without any attempts to bypass safety filters or override system instructions.
  • [DATA_EXFILTRATION]: No evidence of credential harvesting or data exfiltration. Operations are confined to Snowflake database objects and official SAP/Snowflake integration endpoints. All external URL references target official documentation or the author's repositories.
  • [COMMAND_EXECUTION]: Shell and file tools are used for routine tasks such as reading and writing schema definitions (CSN JSON) locally. Administrative Snowflake operations require specific privileges, and the skill correctly directs users to administrators when these are missing, adhering to the principle of least privilege.
  • [EXTERNAL_DOWNLOADS]: References to external resources are limited to trusted domains (snowflake.com, sap.com) and the author's official GitHub repositories (Snowflake-Labs), which are recognized as safe vendor resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes database metadata and sample data to automate the generation of data product descriptions and schema definitions. While this involves processing external data, the workflow includes human-in-the-loop review points for metadata and passes the output to a restricted system function, minimizing risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 03:06 AM
Security Audit — agent-trust-hub — manage-zerocopy-sapbdc