MCP Registry

bas-mcp-addon

058c8ef4-41b3-5b03-af95-fbed9cdcb870 | v0.2.3
100/ 100
CRITICAL risk
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
5 days ago
Version
v0.2.3
Artifact
SHA256 D08…DB1
Source
Findings (non-IoC)

Is bas-mcp-addon safe?

bas-mcp-addon plugs SAP Business Application Studio into ADT tooling, letting an AI agent work with ABAP development objects through Cloud Foundry. It declares no special permissions. The destination list the scanner harvested from the code holds entries like 0github.com, 2ev3.as and adt.property. Those strings read as mangled GitHub links and pieces of JavaScript property access on an object named adt.

Twenty-nine findings carry the title MCP-TRANSPORT-HARDCODED-TOKEN, and every one lives under test/: test/cf-connectivity.test.mjs, test/cf-destination.test.mjs, test/cf-runtime.test.mjs and test/mcp-proxy.test.mjs. A hardcoded token would matter if it were a live credential, since anyone with the repository could reuse it against your SAP tenant. In these files the values stand in for a Cloud Foundry login during automated tests, which is how a fixture supplies an authenticated context without asking a developer for a real password.

The rest of the output comes from two noisy sources. Rules that flag JavaScript mentioning API keys or environment variables fired across the package, and the string extractor handed over the fragments listed above. The scan turned up no tool description that tells an agent to hide what it does, no code that reads SSH or AWS credential files, and no call to a destination outside the SAP and GitHub addresses this tool exists to use.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

230 detail rows
Showing 25 of 29 · highest severity first

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file manipulation 30
README.mdsrc/mcp-config.mjstest/copilot-content.test.mjs +27 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 10
test/setup-cf.test.mjstest/launcher.test.mjsscripts/publish-npm.mjs +7 more
-
LOWpostinstall crypto operations 9
src/binary.mjsscripts/install-user-copilot-assets.mjssrc/cf-connectivity.mjs +6 more
-
LOWpostinstall system command 36
test/cf-runtime.test.mjs.github/skills/abap-debugging/SKILL.md.github/agents/abap-runtime-debugger.agent.md +33 more
-
LOWpostinstall environment access 25
src/mcp-config.mjsscripts/build-vsp.mjstest/cf-connectivity.test.mjs +22 more
-
LOWpostinstall registry modification 4
dist/vsp-linux-x64dist/vsp-linux-arm64src/abaplint.mjs +1 more
-
LOWpostinstall obfuscation 8
test/cf-destination.test.mjssrc/cf-connectivity.mjsdist/vsp-linux-x64 +5 more
-
LOWpostinstall network communication 22
src/mcp-config.mjstest/cf-runtime.test.mjstest/discovery.test.mjs +19 more
-
LOWpostinstall file download 13
src/binary.mjssrc/cf-destination.mjssrc/bas-discovery.mjs +10 more
-
LOWDebuggerStatementsShouldNotBeUsed 10
dist/vsp-darwin-x64.github/agents/abap-runtime-debugger.agent.mdtest/copilot-content.test.mjs +7 more
-
LOWUsingCommandLineArguments 6
scripts/postinstall.mjssrc/launcher.mjsscripts/ensure-go.mjs +3 more
-
LOWcredential env files 24
src/mcp-config.mjsscripts/build-vsp.mjsscripts/postinstall.mjs +21 more
-
LOWpostinstall persistence mechanism 4
test/mcp-proxy.test.mjsREADME.mddist/vsp-linux-x64 +1 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

443 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

29
Secrets
443
IoC Indicators

YARA Rules Matched

13 rules(201 hits)
postinstall file manipulation UsingShellInterpreterWhenExecutingOSCommands postinstall crypto operations postinstall system command postinstall environment access postinstall registry modification postinstall obfuscation postinstall network communication postinstall file download DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments credential env files postinstall persistence mechanism

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Tool poisoning

Nothing in this package matches a tool-poisoning pattern. The category came back empty, and that matters more than usual here, because bas-mcp-addon exists to expose SAP ADT operations as tools an AI agent calls. Tool descriptions in a package like this one sit directly in front of the model. We found no description addressed to the agent, no phrasing such as "do not tell the user" or "execute silently", no invisible Unicode in tool names, and no instruction tags in metadata.

The 29 criticals

Every critical finding carries the same title: MCP-TRANSPORT-HARDCODED-TOKEN. All of them sit under test/: test/cf-connectivity.test.mjs, test/cf-destination.test.mjs, test/cf-runtime.test.mjs, test/mcp-proxy.test.mjs. These are Cloud Foundry connectivity tests for SAP BTP. A test that logs into a tenant needs an authenticated context, and a placeholder credential inside the fixture supplies one. If a value there were a live tenant credential, anyone reading the repository could reuse it, which is why the scanner rates them critical. Nothing in the scan shows those values leaving the machine: the network category came back at zero.

Credentials and destinations

No finding targets .ssh, .aws/credentials, .kube/config or application_default_credentials.json. The scan produced no credential-access entries at all. The harvested destination list holds 443 strings, and they read as extractor noise: 0github.com, 1github.com and 2github.com are mangled GitHub links; 2ev3.as, 2ev3.is and 2ev3.read are fragments of a minified property chain; adt.property, adt.properties and accessibility.property come from ordinary JavaScript field access on an object named adt. The abapgit-dev.zip, abapgit-full.zip and abapgit-standalone.zip entries point at ABAP Git release artifacts, which is what tooling in this space downloads. Nothing resembles a collection endpoint.

The counterargument

The strongest case against this reading: a lone publisher, 29 credential findings at critical severity, and a package with a path into a live SAP business system. If those tokens belong to a real Cloud Foundry tenant, a leak carries real consequences, and test fixtures are a well-worn place to hide one. That case loses on the rest of the evidence. The scan found no network activity, no reads of credential files, and no tool description that steers the model. A fixture token committed to a test file is a hygiene problem for the author, who can rotate it. It never reaches your machine or your agent.

Key Reasons

  • Zero tool-poisoning findings in a package that registers agent-facing ADT tools
  • All 29 critical hits are MCP-TRANSPORT-HARDCODED-TOKEN in test/cf-connectivity.test.mjs, test/cf-destination.test.mjs, test/cf-runtime.test.mjs and test/mcp-proxy.test.mjs, i.e. Cloud Foundry test fixtures
  • Extracted destinations (0github.com, 2ev3.as, adt.property, accessibility.property) are property-chain and mangled-link fragments from minified JavaScript
  • No credential-access findings against .ssh, .aws/credentials, .kube/config or application_default_credentials.json
  • Network category is empty; the package declares no permissions or host permissions

False Positive Considerations

  • IoC extractor garbage: mangled github.com links, 2ev3.* property-chain fragments, adt.property and accessibility.property field access
  • Hardcoded tokens limited to test/*.test.mjs fixtures rather than runtime code
  • Code-smell and secret rules matching any JavaScript that references API keys or environment variables
  • High string-extraction volume typical of a bundled Node package

Reviewed 2026-09-28; recommended action: suppress false positive; model confidence 76%.

About This Extension

SAP Business Application Studio MCP entry point for vibing-steampunk ADT tools

Frequently Asked Questions