
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
MCP connector for ABAPilot — AI access to SAP ECC and on-premise S/4HANA. Requires a licensed ABAPilot backend (/ABAPILOT/ namespace) in your SAP system.
Connects any MCP client — Claude, Claude Code, Cursor, ChatGPT — to a licensed ABAPilot backend running inside your SAP system (ECC 6.0 through on-premise S/4HANA).
This package is the free client-side connector. It contains no business logic:
every operation executes inside SAP, gated by the /ABAPILOT/CONFIG whitelist,
the calling user's own SAP authorizations, and logged to /ABAPILOT/AUDIT.
A licensed ABAPilot backend (delivered as an ABAP transport into the
/ABAPILOT/ namespace) is required — request a demo.
{
"mcpServers": {
"abapilot": {
"command": "npx",
"args": ["-y", "abapilot"],
"env": {
"ABAPILOT_URL": "http://<sap-host>:<port>/sap/bc/ZABAPilot",
"ABAPILOT_USER": "<sap-user>",
"ABAPILOT_PASSWORD": "<sap-password>",
"ABAPILOT_CLIENT": "100"
}
}
}
}
Add the block above to your MCP client configuration (e.g. Claude Desktop's
claude_desktop_config.json). Your SAP credentials go only to your SAP
system — never to us or to any third party.
Each tool maps 1:1 to a whitelisted endpoint of the ABAPilot dispatcher in your SAP system. The AI client supplies the reasoning; SAP supplies the data, always under the connecting user's own authorizations.
sap_read_table_data — query SAP table rows with ABAP-style WHERE filteringsap_read_table_structure — field definitions, types and keys of a tablesap_search_tables — find tables in the Data Dictionary by keywordsap_read_code — read ABAP source (programs, classes, function groups)sap_read_where_used — cross-reference lookup (what uses X / what does X use)sap_syntax_check — validate ABAP source against the system's release rulessap_read_dumps — ST22 runtime errors (short dumps)sap_read_jobs — SM37 background jobs, status and runtimesThe available endpoints are controlled by the /ABAPILOT/CONFIG whitelist in
your system — remove an endpoint there and the corresponding tool stops
working, no client change needed.
| Variable | Required | Description |
|---|---|---|
ABAPILOT_URL | yes | Base URL of the ABAPilot SICF service |
ABAPILOT_USER / ABAPILOT_PASSWORD | yes* | SAP credentials (basic auth) |
ABAPILOT_TOKEN | yes* | Bearer token alternative to user/password |
ABAPILOT_CLIENT | no | SAP client (Mandant), sent as sap-client URL parameter |
ABAPILOT_TLS_INSECURE | no | 1 to skip TLS verification (dev systems only) |
* one of the two authentication methods.
© Crimson Consulting SL — connector released under MIT; the ABAPilot backend is a commercial product.
FAQs
MCP connector for ABAPilot — AI access to SAP ECC and on-premise S/4HANA. Requires a licensed ABAPilot backend (/ABAPILOT/ namespace) in your SAP system.
The npm package abapilot receives a total of 43 weekly downloads. As such, abapilot popularity was classified as not popular.
We found that abapilot demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.