Atlas / MCP servers / hatrigt / Hana

HanaSAFE

mcp/hatrigt/hana

SAP HANA MCP server — Enterprise Model Context Protocol server for SAP HANA. Use with Claude Code, VS Code. npm: hana-mcp-server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
38 35r · 3w · 0d
Transport
—
License
MIT
Stars
70
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/hana-mcp-server) [](https://www.npmjs.com/package/hana-mcp-server) [](https://nodejs.org/) [](LICENSE) [](https://modelcontextprotocol.io/)

SAP HANA MCP Server implements the Model Context Protocol for SAP HANA and SAP HANA Cloud. AI clients discover schema, run SQL with guardrails, and optionally merge business/domain metadata so agents interpret codes and tables consistently—without replacing your database as the system of record.

📚 Documentation

✅ Prerequisites

  • Node.js 18+
  • A SAP HANA or SAP HANA Cloud database reachable on the SQL port from the machine running the server
  • An MCP client (Claude Desktop, Claude Code, VS Code, Cursor, Cline, Windsurf, or custom HTTP client)
  • Credentials supplied via env (see Security)

📦 Installati

Read from source at commit c912c4910a7fOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add hana-mcp-server --env HANA_PASSWORD=${HANA_PASSWORD} --env MCP_HTTP_AUTH_ENABLED=${MCP_HTTP_AUTH_ENABLED} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "hana-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "HANA_PASSWORD": "${HANA_PASSWORD}",
        "MCP_HTTP_AUTH_ENABLED": "${MCP_HTTP_AUTH_ENABLED}"
      }
    }
  }
}
03

Exposed tools (38)

35 read · 3 write · 0 destructive.

ToolRiskDescription
goalreadWhat the query should achieve
hana_connection_testreadTest HANA database connection and show configuration
hana_describe_functionreadReturn parameter names, types, data types, and positions for a function from SYS.FUNCTION_PARAMETERS.
hana_describe_indexreadDescribe the structure of a specific index
hana_describe_procedurereadReturn parameter names, types (IN/OUT/INOUT), data types, and positions from SYS.PROCEDURE_PARAMETERS.
hana_describe_tablereadDescribe the structure of a specific table
hana_describe_viewreadReturn the view definition (SQL) and column metadata from SYS.VIEWS and SYS.VIEW_COLUMNS.
hana_explain_planwriteRun EXPLAIN PLAN for a SELECT/WITH query and return operator tree from EXPLAIN_PLAN_TABLE. Only SELECT/WITH are accepted.
hana_explain_tablereadReturn column metadata merged with optional business semantics from HANA_SEMANTICS_PATH or HANA_SEMANTICS_URL (JSON keys: SCHEMA.TABLE or DB.SCHEMA.TABLE when catalog_database is set). Optional catalog_database reads SYS.* from another MDC database (e.g. HSP).
hana_get_column_statsreadRetrieve column statistics (distinct count, null count, min/max) from SYS.COLUMN_STATISTICS (cached) or via live COUNT queries (live=true). With live=true a specific column_name is required.
hana_get_ddlwriteRetrieve the DDL (CREATE statement) for a TABLE, VIEW, PROCEDURE, FUNCTION, TRIGGER, or SEQUENCE from SYS.OBJECT_DEFINITION. Requires appropriate privileges.
hana_get_dependenciesreadShow what an object depends on or what depends on it, from SYS.OBJECT_DEPENDENCIES. Capped at 200 rows.
hana_get_expensive_queriesreadReturn the most expensive statements from M_EXPENSIVE_STATEMENTS ordered by duration. Requires MONITORING privilege.
hana_get_partition_inforeadReturn partition metadata (type, level, record count, loaded state) from SYS.TABLE_PARTITIONS. Returns empty result for unpartitioned tables.
hana_get_sample_datareadFetch the first N rows from a table using SELECT TOP. Result is shaped by the same row/column/cell caps as hana_execute_query.
hana_get_session_inforeadReturn CURRENT_USER, CURRENT_SCHEMA, connected database name, SYSTEM_ID, and HANA version from DUMMY and M_DATABASE.
hana_get_table_statsreadReturn row count, table type, column-store flag, primary key flag, and disk size (requires MONITORING privilege for disk size) from SYS.TABLES and SYS.M_TABLE_SIZES.
hana_list_calculation_viewsreadList calculation views from the _SYS_BIC schema (SAP BW/S4 analytical views). Supports prefix filter and pagination.
hana_list_constraintsreadList primary key, unique, check, and foreign key constraints for a table (SYS.CONSTRAINTS + SYS.REFERENTIAL_CONSTRAINTS).
hana_list_foreign_keysreadList referential constraints (foreign keys) showing column, referenced table/column, and delete rule from SYS.REFERENTIAL_CONSTRAINTS.
hana_list_functionsreadList scalar and table functions from SYS.FUNCTIONS. Supports prefix filter and pagination.
hana_list_indexesreadList all indexes for a specific table
hana_list_privilegesreadList effective privileges for a user (or CURRENT_USER if omitted) from SYS.EFFECTIVE_PRIVILEGES. Requires CATALOG READ privilege or querying own privileges.
hana_list_proceduresreadList stored procedures and their parameter counts from SYS.PROCEDURES.
hana_list_schemasreadList schemas in the HANA database with optional prefix filter and pagination (HANA_LIST_DEFAULT_LIMIT / offset).
hana_list_sequenceswriteList sequences from SYS.SEQUENCES, showing start, min, max, increment, cycle, and cache settings.
hana_list_synonymsreadList synonyms in a schema from SYS.SYNONYMS, showing target object schema, name, and type.
hana_list_tablesreadList tables in a schema with optional name prefix and pagination (HANA_LIST_DEFAULT_LIMIT / offset).
hana_list_viewsreadList views in a schema from SYS.VIEWS. Supports prefix filter and pagination.
hana_query_builderreadBuild a SQL query for HANA database
hana_query_next_pagereadFetch the next page of a truncated SELECT using snapshotId from a previous hana_execute_query result (same SQL and parameters; TTL HANA_QUERY_SNAPSHOT_TTL_MS).
hana_schema_explorerreadExplore HANA database schemas and tables
hana_search_columnsreadFind all columns matching a LIKE pattern across all tables (or within a schema). Uses SYS.TABLE_COLUMNS. Results capped at 1000.
hana_search_tablesreadFind all tables matching a LIKE pattern across all schemas (or within a specific schema). Uses SYS.TABLES. Results capped at 2000.
hana_show_configreadShow the HANA database configuration
hana_show_env_varsreadShow all HANA-related environment variables (for debugging)
hana_test_connectionreadTest connection to HANA database
schemasreadList of schema names in the HANA database
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.json
.markdownlint.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
hana-mcp-ui/src/components/layout/VerticalSidebar.jsx:3
import { cn } from '../../utils/cn';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
hana-mcp-ui/src/components/ui/DatabaseTypeBadge.jsx:1
import { getDatabaseTypeColor, getDatabaseTypeShortName } from '../../utils/databaseTypes'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
hana-mcp-ui/src/components/ui/GlassCard.jsx:2
import { cn } from '../../utils/cn'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
hana-mcp-ui/src/components/ui/GlassCard.jsx:3
import { colors, shadows, borderRadius } from '../../utils/theme'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
hana-mcp-ui/src/components/ui/GradientButton.jsx:2
import { cn } from '../../utils/cn'
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:144
**Cursor / local IDE over HTTP:** set `HANA_*` in the shell (or process manager) that runs `start:http`, then add an HTTP MCP entry with `url` `http://127.0.0.1:3100/mcp` (`"type": "fetch"` or `"type"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:148
| Endpoint | `POST` JSON-RPC to `/mcp` (default base `http://127.0.0.1:3100`) |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-http-mcp.md:3
The server exposes **Streamable HTTP** MCP at **`POST /mcp`** (default `http://127.0.0.1:3100/mcp`). HANA credentials apply to the **Node process** that runs the HTTP server, not to the IDE MCP entry
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-http-mcp.md:34
"url": "http://127.0.0.1:3100/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-http-mcp.md:43
curl -s http://127.0.0.1:3100/mcp
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
hana-mcp-ui/package.json
@heroicons/react, @tailwindcss/forms, @vitejs/plugin-react, autoprefixer, axios, chalk, clsx, cors
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@sap/hana-client, axios, jose, nodemon
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/local-http-mcp.md:3
The server exposes **Streamable HTTP** MCP at **`POST /mcp`** (default `http://127.0.0.1:3100/mcp`). HANA credentials apply to the **Node process** that runs the HTTP server, not to the IDE MCP entry
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/local-http-mcp.md:51
The HTTP transport does **not** implement a full OAuth 2.0 **authorization-server** flow (no hosted `/authorize` or `/token` on this app). It behaves as a **resource endpoint**: callers send **`Author
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
tests/README.md:184
The server can also run over HTTP. One JSON‐RPC request per POST; no persistent session.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
docs/hana_mcp_ui.gif
docs/hana_mcp_ui.gif
Why it matters. 4632059 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
hana-mcp-ui/hana_mcp_ui.gif
hana-mcp-ui/hana_mcp_ui.gif
Why it matters. 4632059 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c912c4910a7ffull audit observations/trust-audit/mcp-server/hatrigt__hana.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c912c4910a7fSAFEB89first audit
06

Questions

What is the Hana MCP server?

SAP HANA MCP server — Enterprise Model Context Protocol server for SAP HANA. Use with Claude Code, VS Code. npm: hana-mcp-server

What tools does Hana expose?

38 in total: 35 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Hana safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Hana need?

It reads HANA_PASSWORD and MCP_HTTP_AUTH_ENABLED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (c912c4910a7f), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement