All skills
secondsky avatar

/sap-dependency-security

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. Use when upgrading deps, configuring security policies, preventing supply chain attacks, pinning SAP MCP servers, or reviewing SAP CAP/UI5/Fiori/HANA/Datasphere/SAC/BTP/ABAP dependency workflows.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-dependency-security

This session only. Nothing lands on disk.

README.md

≈237 tokens on demand. Your agent reads this file only when SKILL.md points to it.

SAP Dependency Security Skill

SAP dependency security and upgrade orchestration guidance for JavaScript, Node.js, MCP servers, and multi-language projects.

Capability Index

Capability Status
Commands 1: /sap-dependency-upgrade-plan
Agents 0
Hooks Yes: hooks/hooks.json
MCP No
LSP No
Source Freshness last_verified: 2026-06-14; dependency-security hook behavior validated locally.
Verification npm run validate; package registry freshness depends on current lockfile evidence.

Trigger Keywords

  • dependency upgrades
  • supply-chain protection
  • lockfile hardening
  • package manager security
  • cooldown policy
  • Dependabot
  • Renovate
  • npm
  • pnpm
  • Bun
  • Yarn
  • Deno
  • CI security
  • SAP dependency security
  • SAP MCP server pins
  • CAP/UI5/Fiori dependency policy
  • HANA/Datasphere/SAC MCP trust
  • BTP/CF/mbt dependency review
  • ABAP/gCTS transport review

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a comprehensive framework for SAP dependency security, focusing on supply chain protection, lockfile hardening, and secure upgrade orchestration. It promotes industry best practices such as cooldown periods for new package releases, blocking post-install scripts, and using dedicated secrets management tools to avoid plaintext environment variables. The skill is well-documented, uses established security tools, and includes specific policies for hardening SAP-related MCP servers.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: CRITICAL · 2 issues

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2026-06-14",
  "known_issues": []
}

README badge

README badge for secondsky/sap-skills/sap-dependency-security