Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add likweitan/abap-skills --skill authorization-iamgit clone --depth 1 https://github.com/likweitan/abap-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/likweitan/abap-skills/authorization-iam)<a href="https://agentmods.dev/skills/likweitan/abap-skills/authorization-iam"><img src="https://agentmods.dev/badge/skills/likweitan/abap-skills/authorization-iam/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/likweitan/abap-skills/authorization-iam"><img src="https://agentmods.dev/badge/skills/likweitan/abap-skills/authorization-iam.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00163 | $0.02276 |
| Opus 5 | $0.00081 | $0.01138 |
| Sonnet 5 | $0.00033 | $0.00455 |
| Haiku 4.5 | $0.00016 | $0.00228 |
Grade A, and why
authorization-iam scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- authorization-iam — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 333 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Authorization & IAM
Guide for implementing authorization checks and identity/access management in ABAP Cloud and on-premise systems.
Workflow
-
Determine the user's goal:
- Implementing authorization checks in ABAP code
- Creating CDS access controls (DCL)
- Setting up IAM apps, business catalogs, and business roles (ABAP Cloud)
- Managing PFCG roles (on-premise)
- Defining custom authorization objects
- Understanding restriction types
-
Identify the platform:
- ABAP Cloud (BTP or S/4HANA embedded) → IAM apps + business catalogs +
CL_ABAP_AUTHORIZATION - On-premise / Standard ABAP → PFCG roles +
AUTHORITY-CHECK
- ABAP Cloud (BTP or S/4HANA embedded) → IAM apps + business catalogs +
-
Guide implementation with the appropriate authorization model
Authorization Models
ABAP Cloud (BTP / S/4HANA Cloud)
IAM App → Business Catalog → Business Role → Business User
↑
Restriction Type (field-level restrictions)
On-Premise (Standard ABAP)
Authorization Object → PFCG Role → User Assignment
↑
Authorization Fields + Permitted Values
Authorization Checks in Code
ABAP Cloud — CL_ABAP_AUTHORIZATION
"Check authorization using released API
DATA(lo_auth) = cl_abap_authorization=>check_authorization(
EXPORTING
authorization_object = 'Z_MY_AUTH'
authorizations = VALUE #(
( field = 'ACTVT' value = '03' ) "Display
( field = 'ZCARR' value = lv_carrier )
) ).
IF lo_auth->is_authorized( ) = abap_false.
"User not authorized
RAISE EXCEPTION TYPE zcx_not_authorized.
ENDIF.
On-Premise — AUTHORITY-CHECK
AUTHORITY-CHECK OBJECT 'Z_MY_AUTH'
ID 'ACTVT' FIELD '03'
ID 'ZCARR' FIELD lv_carrier.
IF sy-subrc <> 0.
MESSAGE e001(z_msg) WITH lv_carrier.
RETURN.
ENDIF.
Activity Values (ACTVT)
| Value | Activity |
|---|---|
01 |
Create |
02 |
Change |
03 |
Display |
06 |
Delete |
16 |
Execute |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 333 lines · 163 tokens per session scan A c083835eb2d3
authorization-iam is a skill published in the GitHub repository likweitan/abap-skills (60 stars, last pushed 15d ago), licensed MIT. It adds 163 tokens to every session and 2,276 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
sap-expert
Expert in SAP ERP systems, ABAP programming, SAP HANA, S/4HANA, Fiori applications, and SAP integration patterns including OData, RFC, and IDoc. Use when the user mentions ERP, enterprise, business apps, ABAP, HANA, or S/4HANA, or when the task involves SAP Ecosystem, ABAP Development, Integration Technologies, or…
sap-transport-gate
Use for SAP Transport Request pre-release gate review (QAS/PRD). Triggers on any TR number in input (pattern: uppercase letters + K + 6 digits, e.g., DEVK900123, ECDK943668). Asks user: code-quality-only or functional+code review. Performs 10-dimension risk review of ABAP/CDS/DDIC source, object list, dependencies…
abap-code-review
Performs structured pre-release security and quality review of SAP ABAP programs across 9 dimensions (SEC, AUTH, DATA, PERF, STD, INTERFACE, CHANGE, COMP, FUNC), producing a formal sign-off-ready Markdown assessment report. Trigger when the user asks to review, audit, assess, or check ABAP code before release …
sap-sac-custom-widget
SAP Analytics Cloud (SAC) Custom Widget development. Use when building custom visualizations, extending SAC with Web Components, or creating Widget Add-Ons. Covers JSON metadata, JavaScript Web Components, lifecycle functions, data binding with feeds, styling/builder panels, property/event/method definitions…
sap-sac-planning
SAP Analytics Cloud (SAC) planning guidance for planning models, planning-enabled stories, data actions, multi actions, version management, data locking, calendar/input workflows, allocations, value driver trees, BPC live planning, and Seamless Planning with SAP Datasphere. Use this for planning design, planning APIs…
sap-dependency-security
SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. Use when upgrading deps, configuring security policies, preventing supply chain attacks, pinning SAP MCP servers, or reviewing SAP CAP/UI5/Fiori/HANA/Datasphere/SAC/BTP/ABAP dependency…