CAP PluginSAFE
MCP (Model Context Protocol) server plugin for CAP NodeJS
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This implementation is based on the Model Context Protocol (MCP) put forward by Anthropic. For more information on MCP, please have a look at their official documentation.
CAP-MCP Plugin
A CAP (Cloud Application Programming) plugin that automatically generates Model Context Protocol (MCP) servers from your CAP services using simple annotations. Transform your CAP OData services into AI-accessible resources, tools, and prompts with minimal configuration.
🚀 The Power of MCP for CAP Applications
The Model Context Protocol bridges the gap between your enterprise data and AI agents. By integrating MCP with your CAP applications, you unlock:
- AI-Native Data Access: Your CAP services become directly accessible to MCP enabled AI agents like Claude, enabling natural language queries against your business data
- Enterprise Integration: Seamlessly connect AI tools to your SAP systems, databases, and business logic
- Intelligent Automation: Enable AI agents to perform complex business operations by combining multiple CAP service calls
- Developer Productivity: Allow AI assistants to help developers understand, query, and work with your CAP data models
- Business Intelligence: Transform your structured business data into AI-queryable resources for insights and analysis
🚀 Quick Setup
Want to read the full documentation? Find it here
Prerequisites
- Node.js: Version 18 or higher
- SAP CAP: Version 10 or higher
- Express: Version 5 or higher
- TypeScript: Optional but recommended
3f6ce31d422dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add demo -- npx -y [email protected]
{
"mcpServers": {
"demo": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (23)
23 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
assistant | read | Prompt with assistant role |
cap_describe_model | read | |
complex | read | A complex prompt with multiple variables |
empty-inputs | read | Prompt with empty inputs array |
give-me-book-abstract | read | Gives an abstract of a book based on the title |
multi-type | read | Prompt with different input types |
no-arg | read | Prompt without arguments |
no-input | read | A prompt without inputs |
p | read | d |
p1 | read | d1 |
prompt1 | read | Description 1 |
prompt2 | read | Second prompt |
simple-prompt | read | A simple test prompt |
special | read | Prompt with special characters |
test | read | test |
test-all-arrays | read | test all array types |
test-array | read | test array parameters |
test-complex-array | read | test complex array parameters |
test-explicit-optional | read | test explicit notNull false |
test-mixed | read | test mixed parameters |
test-name | read | test-description |
test-optional | read | test optional parameters |
test-prompt | read | A test prompt for auth testing |
Trust audit
SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (15)
streamable-http
.prettierignore
.release-it.json
.nojekyll
.cdsrc.json
"eval(malicious_code)",
"odata://CatalogService/books?filter=test&eval(hack)=injection",
import { CAPConfiguration } from "../../src/config/types";import { CAPConfiguration } from "../../src/config/types";const configModule = require("../../src/config/loader");const configModule = require("../../src/config/loader");import McpPlugin from "../../../src/mcp";
"odata://Service/entity?filter=test&admin=hack", // Zero-width joiner
@modelcontextprotocol/sdk, @sap/xssec, cors, helmet, zod, zod-to-json-schema, @cap-js/cds-types, @release-it/conventional-changelog
@sap/cds, express, @cap-js/sqlite, @cap-js/cds-types
Gates applied: no_behavioural_pass.
3f6ce31d422dfull audit observations/trust-audit/mcp-server/gavdilabs__cap-plugin.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 3f6ce31d422d | SAFE | B | 87 | first audit |
Questions
What is the CAP Plugin MCP server?
MCP (Model Context Protocol) server plugin for CAP NodeJS
What tools does CAP Plugin expose?
23 in total: 23 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CAP Plugin safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does CAP Plugin need?
No credential environment variables were found in its source, so it appears to need none.
How does CAP Plugin run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as demo at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (3f6ce31d422d), read on 2026-10-07. The repository is watched and re-audited when it changes.