SAP OData MCP Server (YXH940724/B2B_SAP_Project) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 7 tools. No publisher has claimed this listing.
MCP server for interacting with SAP S/4HANA OData services. It enables querying and controlled creation/update of sales orders, products, customers, and pricing conditions, with safety features like dry-run mode and ETag-based updates.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
YXH940724
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
PORTAL_DB_PATH运行 npm run build 后,以环境变量方式提供 .env.example 中的配置并执行 npm run start:web。门户在 http://localhost:3000 提供客户自助注册、客户号登录、A305/PR00 价格校验、购物车和“确认同步 SAP”操作。客户密码以哈希保存于 指定的 SQLite 文件,不写入 SAP。PORTAL_PORTPORTAL_SALES_ORDER_TYPESAP_BUSINESS_PARTNER_SERVICE_URLSAP_CA_CERT_PATH必须通过 信任企业 CA。生产环境拒绝关闭 TLS 证书校验。SAP_CLIENTSAP_ODATA_BASE_URLSAP_PRICING_SERVICE_URLSAP_PRODUCT_SERVICE_URLSAP_REQUEST_TIMEOUT_MSSAP_WRITE_ALLOWED_FIELDS可更新字段由 白名单控制。SAP_WRITE_ENABLED真实写入必须同时满足:=true、dry_run=false,以及工具要求的确认短语。Tool inputs are validated
4/7 tool handlers declare input schemas (57%)
Declare an inputSchema with zod/joi/yup on every tool definition.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tool test coverage
Only 0/7 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Tests pass
npm test failed — tests do not pass
Make sure npm test runs cleanly. Common cause: missing build step or missing env vars.
Shell command execution
1 child_process call — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/yxh940724/b2b_sap_project)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check