development

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, prompt injections, or unauthorized data access commands were found. The skill consists of instructional guidelines (Iron Laws) and checklists for SAP consultants to ensure methodical development and troubleshooting.
  • [SAFE]: The skill exhibits an attack surface for indirect prompt injection because it processes untrusted data such as SAP system logs (ST22, SM21) and ABAP source code. However, the risk is mitigated by the rigorous multi-step validation gates, such as mandatory ATC checks, security audits, and code reviews, which are embedded within the instruction set.
  • Ingestion points: troubleshooting/SKILL.md (diagnostic logs) and program-to-spec/SKILL.md (ABAP source code).
  • Boundary markers: None explicitly defined in the instructions for data isolation.
  • Capability inventory: The skill set includes capabilities to generate, activate, and manage SAP transports for ABAP code via autopilot/SKILL.md and development-workflow/SKILL.md.
  • Sanitization: Not specified in the current instruction set.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 01:29 PM
Security Audit — agent-trust-hub — development