66
/ 100
17 days ago
official

SAP MCP Server

Solana-native MCP gateway for SAP, DeFi tools, SNS identity, and x402 payments.

OOBE-PROTOCOL/sap-mcp· npm: @oobe-protocol-labs/sap-mcp-server· listed on official
Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 7 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 7 credentials: APPLE_APP_SPECIFIC_PASSWORD, SAP_EXTERNAL_SIGNER_AUTH_TOKEN, SAP_HTTP_API_KEY, SAP_MCP_AUTH_SECRET, SAP_MCP_BENTO_API_KEY, SAP_MCP_FACILITATOR_AUTH_TOKEN, SAP_MCP_X402_FACILITATOR_PUBLIC_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies7 high16 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highelectron@39.2.7GHSA-532v-xpq5-8h95

Electron: Use-after-free in offscreen child window paint callback

highelectron@39.2.7GHSA-8337-3p73-46f4

Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks

highelectron@39.2.7GHSA-9wfr-w7mm-pc7f

Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretAPPLE_APP_SPECIFIC_PASSWORD
configAPPLE_ID
configAPPLE_TEAM_ID
configCSC_LINK
configNO_COLOR
configSAP_ENABLE_CACHE
configSAP_ENABLE_HTTP
configSAP_ENABLE_RATE_LIMIT
🔐 secretSAP_EXTERNAL_SIGNER_AUTH_TOKEN
🔐 secretSAP_HTTP_API_KEY
configSAP_MCP_ADDRESS_BLACKLIST
configSAP_MCP_ADDRESS_WHITELIST
configSAP_MCP_ALLOWED_HOURS
configSAP_MCP_ALLOW_ENV_CONFIG_OVERRIDE"": "false",
configSAP_MCP_API_KEYS
🔐 secretSAP_MCP_AUTH_SECRET
configSAP_MCP_AUTH_TYPE
configSAP_MCP_BENTO_AGENT_ID
🔐 secretSAP_MCP_BENTO_API_KEY
configSAP_MCP_BENTO_ENDPOINT
configSAP_MCP_CONFIG_PATH
configSAP_MCP_DESKTOP_DEV_URL
configSAP_MCP_ESCALATION_TOOLS
🔐 secretSAP_MCP_FACILITATOR_AUTH_TOKEN
configSAP_MCP_FACILITATOR_HOST
configSAP_MCP_FACILITATOR_NETWORKS
configSAP_MCP_FACILITATOR_PATH_PREFIX
configSAP_MCP_FACILITATOR_PORT
configSAP_MCP_FACILITATOR_RPC_FALLBACK_URLS
configSAP_MCP_FACILITATOR_RPC_URL
configSAP_MCP_FACILITATOR_SIGNER_PATH
configSAP_MCP_HOST
configSAP_MCP_HTTP_STATELESS
configSAP_MCP_LOG_FORMAT
configSAP_MCP_LOG_LEVEL
configSAP_MCP_MODE
configSAP_MCP_MONETIZATION_ENABLED
configSAP_MCP_NO_COLOR
configSAP_MCP_PAYMENT_LEDGER_REDIS_STREAM
configSAP_MCP_POLICY_FAIL_OPEN
configSAP_MCP_POLICY_LOGGING
configSAP_MCP_POLICY_MODE
configSAP_MCP_PORT
configSAP_MCP_PROFILE
configSAP_MCP_PROGRAM_BLACKLIST
configSAP_MCP_PROGRAM_WHITELIST
configSAP_MCP_PUBLIC_URL
configSAP_MCP_RATE_LIMITS
configSAP_MCP_REDIS_URL
configSAP_MCP_REGISTRY_AUTH_FILE
configSAP_MCP_REGISTRY_AUTH_RECORD
configSAP_MCP_REMOTE_RATE_LIMIT_ENABLED
configSAP_MCP_REMOTE_RATE_LIMIT_PER_MINUTE
configSAP_MCP_REMOTE_RATE_LIMIT_PREFIX
configSAP_MCP_RPC_URL
configSAP_MCP_SPEND_LIMITS
configSAP_MCP_USE_REDIS
configSAP_MCP_X402_FACILITATOR_FEE_PAYER
🔐 secretSAP_MCP_X402_FACILITATOR_PUBLIC_KEY
configSAP_WALLET_PATH
configXDG_CONFIG_HOME
configXDG_DATA_HOME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/oobe-protocol-labs-sap-mcp-server-gmvqrg)](https://m8ven.ai/mcp/oobe-protocol-labs-sap-mcp-server-gmvqrg)
commit: d221def95e02705fe6727dd5c6665a4811ff85f6
code hash: ec56f606da6374155f506b0cd2f69139d376c8fa6a9ddb40fea8e8491a7e836b
verified: 7/14/2026, 8:35:07 AM
view raw JSON →