Oathe Security Badge

Is amitlals/sap-rpt1-oss-predictor safe?

https://github.com/amitlals/sap-rpt1-oss-predictor

94
SAFE

This skill is a legitimate educational tool for SAP data analysis using SAP's open-source RPT-1-OSS tabular foundation model. It contains standard Python data science scripts with no malicious behavior detected. All canary files remained intact during installation, and network activity was limited to normal GitHub repository cloning.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 95/100 · 25%
Code Execution 90/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (1)

LOW External Model Dependencies -10

The skill downloads and executes machine learning models from Hugging Face, which could theoretically pose supply chain risks if the model repository were compromised. However, this uses SAP's official model repository (SAP/sap-rpt-1-oss), significantly reducing this risk.