sap-commerce

Pass

Audited by Gen Agent Trust Hub on Feb 20, 2026

Risk Level: SAFECREDENTIALS_UNSAFE
Full Analysis
  • SAFE (SAFE): The skill provides standard SAP Commerce development templates including Java source code, XML configurations, and ImpEx scripts. All code is idiomatic and lacks malicious patterns.
  • COMMAND_EXECUTION (SAFE): Included shell scripts such as generate-extension.sh and query-items.sh are legitimate developer tools. They perform expected operations like scaffolding project structures or interacting with the SAP Commerce administration console.
  • CREDENTIALS_UNSAFE (LOW): Sample data ImpEx scripts contain hardcoded default passwords (e.g., 'Test@123'). While intended for local development environments, this is a best-practice violation for production systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 20, 2026, 11:22 PM