sap-commerce
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFECREDENTIALS_UNSAFE
Full Analysis
- SAFE (SAFE): The skill provides standard SAP Commerce development templates including Java source code, XML configurations, and ImpEx scripts. All code is idiomatic and lacks malicious patterns.
- COMMAND_EXECUTION (SAFE): Included shell scripts such as
generate-extension.shandquery-items.share legitimate developer tools. They perform expected operations like scaffolding project structures or interacting with the SAP Commerce administration console. - CREDENTIALS_UNSAFE (LOW): Sample data ImpEx scripts contain hardcoded default passwords (e.g., 'Test@123'). While intended for local development environments, this is a best-practice violation for production systems.
Audit Metadata