All skills
secondsky avatar

/sap-dependency-security

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. Use when upgrading deps, configuring security policies, preventing supply chain attacks, pinning SAP MCP servers, or reviewing SAP CAP/UI5/Fiori/HANA/Datasphere/SAC/BTP/ABAP dependency workflows.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-dependency-security

This session only. Nothing lands on disk.

referencessap-dependency-risk-matrix.md

≈831 tokens on demand. Your agent reads this file only when SKILL.md points to it.

SAP Dependency Risk Matrix

Use this reference when a dependency update touches SAP development tooling, SAP runtime libraries, deployment assets, or MCP servers. The default SAP posture is stricter than the generic dependency workflow: 14-day cooldown, exact pins for executable tooling, frozen installs, and manual review for tenant-connected tools.

Ecosystem Matrix

Area Typical Artifacts Main Risks Required Checks
CAP / UI5 / Fiori Node tooling package.json, lockfiles, .npmrc, ui5.yaml, mta.yaml Lifecycle scripts, transitive tooling compromise, UI build drift Exact tool pins, frozen install, script blocking, lockfile review, npm audit or Socket/OSV
SAP MCP servers .mcp.json, env vars, local source checkout Executing unreviewed packages with SAP project or tenant access Exact npm pin or source commit pin, no @latest, inventory entry, validator pass
SAP Cloud SDK Java / CAP Java pom.xml, mvnw, .mvn/maven.config BOM drift, repository substitution, vulnerable transitive JARs Maven wrapper, strict checksums, dependency tree review, OSV-Scanner
Gradle Java services build.gradle, settings.gradle, gradle.lockfile Dynamic versions, unverified artifacts, plugin portal drift Dependency locking, verification metadata, no dynamic versions, OSV-Scanner
SAP AI SDK / HANA ML Python pyproject.toml, requirements*.txt, uv.lock Unlocked wheels, extras pulling broad provider trees, typosquats Lockfile, hashes where practical, pip-audit, uv pip compile or equivalent
Containers / Kyma Dockerfile, Helm/Kubernetes manifests Base image CVEs, mutable tags, privileged runtime Digest-pinned base images, Trivy scan, non-root user, minimal capabilities
BTP / CF / mbt tooling mta.yaml, xs-security.json, pipeline scripts Global CLI drift, service binding changes, accidental deploy target changes Pin CLI versions in CI, review service bindings, verify cf target, inspect MTAR diff
ABAP / gCTS / transports Software components, transport requests, abapGit repos Transport dependency gaps, unreviewed generated objects, cross-system drift Import queue review, dependency order check, ATC/security checks, rollback transport

SAP Defaults

  • Use a 14-day cooldown for SAP enterprise projects unless a maintainer records an exception.
  • Prefer project-local tooling over global installs in CI.
  • Treat MCP servers as executable dependencies, not passive documentation.
  • Keep runtime authorization design in the relevant SAP skill. This skill covers dependency, package, source, and executable trust.
  • For credentialed MCPs, review both package/source trust and whether the configured credential is least-privilege.

Review Prompts

  • What executable code changes during this update: package tarball, JAR, wheel, container layer, or source checkout?
  • Does the update alter tenant access, deployment targets, service bindings, or generated artifacts?
  • Is the new version old enough for the SAP cooldown, or is there an explicit exception?
  • Can CI reproduce the install from locked inputs without network-time latest resolution?
  • Is rollback possible without manually reconstructing tool versions or generated output?

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a comprehensive framework for SAP dependency security, focusing on supply chain protection, lockfile hardening, and secure upgrade orchestration. It promotes industry best practices such as cooldown periods for new package releases, blocking post-install scripts, and using dedicated secrets management tools to avoid plaintext environment variables. The skill is well-documented, uses established security tools, and includes specific policies for hardening SAP-related MCP servers.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: CRITICAL · 2 issues

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2026-06-14",
  "known_issues": []
}

README badge

README badge for secondsky/sap-skills/sap-dependency-security