Atlas / MCP servers / gavdilabs / CAP Plugin

CAP PluginSAFE

mcp/gavdilabs/cap-plugin

MCP (Model Context Protocol) server plugin for CAP NodeJS

Verdict
SAFE
Grade
B
Trust score
87 /100
Exposed tools
23 23r · 0w · 0d
Transport
streamable-http
License
NOASSERTION
Stars
61
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This implementation is based on the Model Context Protocol (MCP) put forward by Anthropic. For more information on MCP, please have a look at their official documentation.

CAP-MCP Plugin

A CAP (Cloud Application Programming) plugin that automatically generates Model Context Protocol (MCP) servers from your CAP services using simple annotations. Transform your CAP OData services into AI-accessible resources, tools, and prompts with minimal configuration.

🚀 The Power of MCP for CAP Applications

The Model Context Protocol bridges the gap between your enterprise data and AI agents. By integrating MCP with your CAP applications, you unlock:

  • AI-Native Data Access: Your CAP services become directly accessible to MCP enabled AI agents like Claude, enabling natural language queries against your business data
  • Enterprise Integration: Seamlessly connect AI tools to your SAP systems, databases, and business logic
  • Intelligent Automation: Enable AI agents to perform complex business operations by combining multiple CAP service calls
  • Developer Productivity: Allow AI assistants to help developers understand, query, and work with your CAP data models
  • Business Intelligence: Transform your structured business data into AI-queryable resources for insights and analysis

🚀 Quick Setup

Want to read the full documentation? Find it here

Prerequisites

  • Node.js: Version 18 or higher
  • SAP CAP: Version 10 or higher
  • Express: Version 5 or higher
  • TypeScript: Optional but recommended

Read from source at commit 3f6ce31d422dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add demo -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "demo": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (23)

23 read · 0 write · 0 destructive.

ToolRiskDescription
assistantreadPrompt with assistant role
cap_describe_modelread
complexreadA complex prompt with multiple variables
empty-inputsreadPrompt with empty inputs array
give-me-book-abstractreadGives an abstract of a book based on the title
multi-typereadPrompt with different input types
no-argreadPrompt without arguments
no-inputreadA prompt without inputs
preadd
p1readd1
prompt1readDescription 1
prompt2readSecond prompt
simple-promptreadA simple test prompt
specialreadPrompt with special characters
testreadtest
test-all-arraysreadtest all array types
test-arrayreadtest array parameters
test-complex-arrayreadtest complex array parameters
test-explicit-optionalreadtest explicit notNull false
test-mixedreadtest mixed parameters
test-namereadtest-description
test-optionalreadtest optional parameters
test-promptreadA test prompt for auth testing
04

Trust audit

SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-it.json
.release-it.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
test/demo/.cdsrc.json
.cdsrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/integration/http-api/mcp-security-boundary.spec.ts:481
"eval(malicious_code)",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/unit/mcp/customUriTemplate-security.spec.ts:299
"odata://CatalogService/books?filter=test&eval(hack)=injection",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/mock-config.ts:1
import { CAPConfiguration } from "../../src/config/types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/test-config-loader.ts:1
import { CAPConfiguration } from "../../src/config/types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/test-config-loader.ts:15
const configModule = require("../../src/config/loader");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/helpers/test-config-loader.ts:47
const configModule = require("../../src/config/loader");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/integration/fixtures/auth-test-server.ts:2
import McpPlugin from "../../../src/mcp";
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
test/unit/mcp/customUriTemplate-security.spec.ts:252
"odata://Service/entity?filter=test&admin=hack", // Zero-width joiner
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @sap/xssec, cors, helmet, zod, zod-to-json-schema, @cap-js/cds-types, @release-it/conventional-changelog
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
test/demo/package.json
@sap/cds, express, @cap-js/sqlite, @cap-js/cds-types
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 3f6ce31d422dfull audit observations/trust-audit/mcp-server/gavdilabs__cap-plugin.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-073f6ce31d422dSAFEB87first audit
06

Questions

What is the CAP Plugin MCP server?

MCP (Model Context Protocol) server plugin for CAP NodeJS

What tools does CAP Plugin expose?

23 in total: 23 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CAP Plugin safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does CAP Plugin need?

No credential environment variables were found in its source, so it appears to need none.

How does CAP Plugin run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as demo at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (3f6ce31d422d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement