All skills
secondsky avatar

/sap-dependency-security

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. Use when upgrading deps, configuring security policies, preventing supply chain attacks, pinning SAP MCP servers, or reviewing SAP CAP/UI5/Fiori/HANA/Datasphere/SAC/BTP/ABAP dependency workflows.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-dependency-security

This session only. Nothing lands on disk.

referencessap-mcp-security.md

≈847 tokens on demand. Your agent reads this file only when SKILL.md points to it.

SAP MCP Security Policy

Use this reference when configuring, updating, or reviewing SAP MCP servers. MCP servers are executable dependencies. Some only read local project metadata, while others use SAP tenant credentials and can call live APIs.

Operation Safety Classes

  • local-only: Operates on local files, local package metadata, local project models, or cached docs.
  • read-only tenant: Reads tenant/system metadata or data and must not mutate tenant state.
  • mutating tenant: Creates, updates, deploys, publishes, triggers, or otherwise changes tenant/system state.
  • destructive: Deletes, drops, revokes, removes, disables, resets, or risks irreversible tenant/system impact.

Require explicit user approval before any mutating tenant or destructive MCP operation. Keep credentials, tokens, service keys, destinations, and tenant URLs in environment variables or local secret managers.

Policy

  • Use exact npm package pins in .mcp.json; never use @latest or a bare package name.
  • Use the SAP MCP inventory (sap-mcp-inventory.json) as the source of approved package/source pins.
  • Use a 14-day SAP cooldown by default. A newer version can be approved only when the inventory records the exception.
  • For local-source MCPs, pin the trusted repository and exact commit SHA. Do not trust a moving branch.
  • Keep tenant credentials in environment variables or local secret managers. Do not commit .env, service keys, or generated local install records.
  • Run npm run validate:mcp-security after changing any plugin .mcp.json.

Current Approved MCP Pins

Plugin MCP Package / Source Approved Pin
sap-cap-capire @cap-js/mcp-server 0.0.5
sapui5 @ui5/mcp-server 0.2.17
sap-fiori-tools @sap-ux/fiori-mcp-server 1.11.7
sap-hana-cli hana-mcp-server 0.3.4
sap-datasphere @mariodefe/sap-datasphere-mcp 1.5.2
sap-sac-scripting secondsky/sap_analytics_cloud_mcp 2020235505d98111c2889598ab2217c1619b6943

SAC Source MCP

The SAC MCP server is source-installed because the trusted secondsky/sap_analytics_cloud_mcp fork is not published as a versioned npm package in this repo. Treat it like a package with a source commit pin:

git clone https://github.com/secondsky/sap_analytics_cloud_mcp
cd sap_analytics_cloud_mcp
git checkout 2020235505d98111c2889598ab2217c1619b6943
npm ci --ignore-scripts
npm run build

Record the installation in .claude/sac-mcp.local.md:

# SAC MCP Installation Record
- Repository: https://github.com/secondsky/sap_analytics_cloud_mcp
- Commit: 2020235505d98111c2889598ab2217c1619b6943
- Path: /absolute/path/to/sap_analytics_cloud_mcp/build/index.js
- Build command: npm ci --ignore-scripts && npm run build
- Env vars configured: SAC_MCP_PATH, SAC_MCP_COMMIT, SAC_BASE_URL, SAC_TOKEN_URL, SAC_CLIENT_ID, SAC_CLIENT_SECRET

Update Workflow

  1. Check the current package or source release metadata.
  2. Apply the 14-day cooldown unless a maintainer records an exception.
  3. Scan the package/source using the command in sap-mcp-inventory.json.
  4. Update .mcp.json manually with the exact version or source commit marker.
  5. Update sap-mcp-inventory.json in the same change.
  6. Run npm run validate:mcp-security and the affected SAP plugin checks.

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a comprehensive framework for SAP dependency security, focusing on supply chain protection, lockfile hardening, and secure upgrade orchestration. It promotes industry best practices such as cooldown periods for new package releases, blocking post-install scripts, and using dedicated secrets management tools to avoid plaintext environment variables. The skill is well-documented, uses established security tools, and includes specific policies for hardening SAP-related MCP servers.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: CRITICAL · 2 issues

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2026-06-14",
  "known_issues": []
}

README badge

README badge for secondsky/sap-skills/sap-dependency-security