Install
$ agentstack add skill-babamba2-superclaude-for-sap-analyze-cbo-obj ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
SC4SAP Analyze CBO Objects
Walks a CBO (Customer Business Object) package, inventories every project-built ABAP element (table, structure, data element, class, interface, function module, program, view, table type), detects which elements are frequently reused inside the package, infers each element's business purpose from its name/fields/descriptions, and persists the result to .sc4sap/cbo/// for downstream skills (program, program-to-spec, create-object, autopilot) to consult before creating anything new.
Projects accumulate Z tables, Z data elements, Z function modules, and ZCL_ classes that encode domain logic. New development too often recreates near-duplicates because nobody has a compact inventory of what already exists. analyze-cbo-obj produces that inventory — once per package — and writes it to a file that later sc4sap: skills read automatically, so the next spec / program / object creation defaults to reusing proven CBO assets.
Every response triggered by this skill MUST begin with [Model: · Dispatched: ] per [../../common/model-routing-rule.md](../../common/model-routing-rule.md) § Response Prefix Convention.
Multi-phase skill. Before each Agent(...) dispatch, emit ▶ phase= () · agent= · model= per [../../common/model-routing-rule.md](../../common/model-routing-rule.md) § Phase Banner Convention.
- Starting development on a module that already has a sizeable Z-package
- Onboarding onto an AMS / support engagement (need a map of custom assets)
- Before
/sc4sap:create-programor/sc4sap:create-objecton a new spec — so reuse is evaluated - User says "analyze CBO", "analyze custom objects", "map Z package", "list frequently used customs", "CBO inventory"
- User wants a code quality review of one object →
/sc4sap:analyze-code - User wants to reverse-engineer ONE program into a spec →
/sc4sap:program-to-spec - User wants to create an object →
/sc4sap:create-object - Package does not yet contain custom objects (CBO discovery is not meaningful)
MANDATORY — runs as Step 0 before any MCP call or user interaction.
Invoke /sc4sap:trust-session with parent_skill=sc4sap:analyze-cbo-obj to pre-grant all MCP tool + file-op permissions for this session (eliminates per-tool "Allow this tool?" prompts during the 8-step walk).
- If
.sc4sap/session-trust.logalready has a line within the last 24h, skip silently. - Otherwise run it and surface the one-line confirmation.
- All subsequent
Agentdispatches within this skill MUST passmode: "dontAsk".
Full spec: see [../trust-session/SKILL.md](../trust-session/SKILL.md).
Orchestration is 3 main-thread Socratic steps (Haiku) + one delegated dispatch to sap-stocker (Sonnet) + a branching hand-off. Detailed spec lives in [workflow-steps.md](./workflow-steps.md).
- Step 1 / 1.5 / 2 (main thread · Haiku) — Socratic intake: package name → flagship programs (optional `
) → module. Frontmattermodel: haiku` pins the main thread to Haiku 4.5 for cost-efficient Q&A — no domain judgment required for intake. - Step 3–7 (delegated · Sonnet 4.6) — One
Agent(...)dispatch tosap-stocker. The stocker runs its own InvestigationProtocol: walk →GetWhereUsedgraph → pin/frequency tiering → business-purpose inference → cross-module gap analysis (per [../../common/active-modules.md](../../common/active-modules.md)) → sensitive-name flagging → persistindex.md+inventory.json→ return aLogic-heavy:flag. Authoritative spec: [../../agents/sap-stocker.md](../../agents/sap-stocker.md) § InvestigationProtocol + § Output_Format. - Step 8 (branching):
- Branch A (
Logic-heavy: false, DDIC-dominant) — canned summary printed by main thread (Haiku). No agent dispatch. - Branch B (
Logic-heavy: true, FM/CLAS/INTF/large-PROG in inventory) — dispatchsap-writer(Haiku 4.5) for a reader-facing briefing: pinned highlights · business-logic assets · cross-module gaps · sensitive objects · next-step hint. Writer BLOCKED → fallback to Branch A.
Main thread NEVER calls GetPackageContents / GetWhereUsed itself for the inventory pass — that context stays inside the stocker so the orchestrator window remains small even for large packages (200+ objects).
.sc4sap/cbo/
└── / # SD, MM, PP, PM, QM, WM, TM, TR, FI, CO, HCM, BW, PS, Ariba
└── / # e.g., ZSD_MAIN
├── index.md # human-readable summary, grouped by object type
├── inventory.json # machine-readable, consumed by sibling skills
└── raw-walk.md # optional full walk (only if asked or small package)
- Discovery:
GetPackage,GetPackageContents,GetPackageTree,SearchObject,GetObjectsByType - Object detail:
GetTable,GetStructure,GetDataElement,GetDomain,GetView,GetClass,GetInterface,GetFunctionGroup,GetFunctionModule,GetProgram,GetObjectInfo - Usage graph:
GetWhereUsed - NEVER used by this skill:
GetTableContents,GetSqlQuery(no row data — DDIC metadata only)
/sc4sap:create-program— reads.sc4sap/cbo///inventory.jsonduring spec drafting to prefer existing CBO elements/sc4sap:program-to-spec— same, for reverse-engineering/sc4sap:create-object— same, to suggest reuse before creation/sc4sap:analyze-code— quality review of ONE object (complementary, not overlapping)
This skill only reads DDIC metadata and where-used relations. It MUST NOT call GetTableContents or GetSqlQuery. Row-level access stays behind the standard blocklist + acknowledge_risk gate. See common/data-extraction-policy.md.
Task: {{ARGUMENTS}}
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: babamba2
- Source: babamba2/superclaude-for-sap
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.