The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v0.2.3
- Artifact
- SHA256 D08…DB1
- Source
- Findings (non-IoC)
Is bas-mcp-addon safe?
bas-mcp-addon plugs SAP Business Application Studio into ADT tooling, letting an AI agent work with ABAP development objects through Cloud Foundry. It declares no special permissions. The destination list the scanner harvested from the code holds entries like 0github.com, 2ev3.as and adt.property. Those strings read as mangled GitHub links and pieces of JavaScript property access on an object named adt.
Twenty-nine findings carry the title MCP-TRANSPORT-HARDCODED-TOKEN, and every one lives under test/: test/cf-connectivity.test.mjs, test/cf-destination.test.mjs, test/cf-runtime.test.mjs and test/mcp-proxy.test.mjs. A hardcoded token would matter if it were a live credential, since anyone with the repository could reuse it against your SAP tenant. In these files the values stand in for a Cloud Foundry login during automated tests, which is how a fixture supplies an authenticated context without asking a developer for a real password.
The rest of the output comes from two noisy sources. Rules that flag JavaScript mentioning API keys or environment variables fired across the package, and the string extractor handed over the fragments listed above. The scan turned up no tool description that tells an agent to hide what it does, no code that reads SSH or AWS credential files, and no call to a destination outside the SAP and GitHub addresses this tool exists to use.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file manipulation | 30 | README.mdsrc/mcp-config.mjstest/copilot-content.test.mjs +27 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 10 | test/setup-cf.test.mjstest/launcher.test.mjsscripts/publish-npm.mjs +7 more | - |
| LOW | postinstall crypto operations | 9 | src/binary.mjsscripts/install-user-copilot-assets.mjssrc/cf-connectivity.mjs +6 more | - |
| LOW | postinstall system command | 36 | test/cf-runtime.test.mjs.github/skills/abap-debugging/SKILL.md.github/agents/abap-runtime-debugger.agent.md +33 more | - |
| LOW | postinstall environment access | 25 | src/mcp-config.mjsscripts/build-vsp.mjstest/cf-connectivity.test.mjs +22 more | - |
| LOW | postinstall registry modification | 4 | dist/vsp-linux-x64dist/vsp-linux-arm64src/abaplint.mjs +1 more | - |
| LOW | postinstall obfuscation | 8 | test/cf-destination.test.mjssrc/cf-connectivity.mjsdist/vsp-linux-x64 +5 more | - |
| LOW | postinstall network communication | 22 | src/mcp-config.mjstest/cf-runtime.test.mjstest/discovery.test.mjs +19 more | - |
| LOW | postinstall file download | 13 | src/binary.mjssrc/cf-destination.mjssrc/bas-discovery.mjs +10 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 10 | dist/vsp-darwin-x64.github/agents/abap-runtime-debugger.agent.mdtest/copilot-content.test.mjs +7 more | - |
| LOW | UsingCommandLineArguments | 6 | scripts/postinstall.mjssrc/launcher.mjsscripts/ensure-go.mjs +3 more | - |
| LOW | credential env files | 24 | src/mcp-config.mjsscripts/build-vsp.mjsscripts/postinstall.mjs +21 more | - |
| LOW | postinstall persistence mechanism | 4 | test/mcp-proxy.test.mjsREADME.mddist/vsp-linux-x64 +1 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
13 rules(201 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Tool poisoning
Nothing in this package matches a tool-poisoning pattern. The category came back empty, and that matters more than usual here, because bas-mcp-addon exists to expose SAP ADT operations as tools an AI agent calls. Tool descriptions in a package like this one sit directly in front of the model. We found no description addressed to the agent, no phrasing such as "do not tell the user" or "execute silently", no invisible Unicode in tool names, and no instruction tags in metadata.
The 29 criticals
Every critical finding carries the same title: MCP-TRANSPORT-HARDCODED-TOKEN. All of them sit under test/: test/cf-connectivity.test.mjs, test/cf-destination.test.mjs, test/cf-runtime.test.mjs, test/mcp-proxy.test.mjs. These are Cloud Foundry connectivity tests for SAP BTP. A test that logs into a tenant needs an authenticated context, and a placeholder credential inside the fixture supplies one. If a value there were a live tenant credential, anyone reading the repository could reuse it, which is why the scanner rates them critical. Nothing in the scan shows those values leaving the machine: the network category came back at zero.
Credentials and destinations
No finding targets .ssh, .aws/credentials, .kube/config or application_default_credentials.json. The scan produced no credential-access entries at all. The harvested destination list holds 443 strings, and they read as extractor noise: 0github.com, 1github.com and 2github.com are mangled GitHub links; 2ev3.as, 2ev3.is and 2ev3.read are fragments of a minified property chain; adt.property, adt.properties and accessibility.property come from ordinary JavaScript field access on an object named adt. The abapgit-dev.zip, abapgit-full.zip and abapgit-standalone.zip entries point at ABAP Git release artifacts, which is what tooling in this space downloads. Nothing resembles a collection endpoint.
The counterargument
The strongest case against this reading: a lone publisher, 29 credential findings at critical severity, and a package with a path into a live SAP business system. If those tokens belong to a real Cloud Foundry tenant, a leak carries real consequences, and test fixtures are a well-worn place to hide one. That case loses on the rest of the evidence. The scan found no network activity, no reads of credential files, and no tool description that steers the model. A fixture token committed to a test file is a hygiene problem for the author, who can rotate it. It never reaches your machine or your agent.
Key Reasons
- Zero tool-poisoning findings in a package that registers agent-facing ADT tools
- All 29 critical hits are MCP-TRANSPORT-HARDCODED-TOKEN in test/cf-connectivity.test.mjs, test/cf-destination.test.mjs, test/cf-runtime.test.mjs and test/mcp-proxy.test.mjs, i.e. Cloud Foundry test fixtures
- Extracted destinations (0github.com, 2ev3.as, adt.property, accessibility.property) are property-chain and mangled-link fragments from minified JavaScript
- No credential-access findings against .ssh, .aws/credentials, .kube/config or application_default_credentials.json
- Network category is empty; the package declares no permissions or host permissions
False Positive Considerations
- IoC extractor garbage: mangled github.com links, 2ev3.* property-chain fragments, adt.property and accessibility.property field access
- Hardcoded tokens limited to test/*.test.mjs fixtures rather than runtime code
- Code-smell and secret rules matching any JavaScript that references API keys or environment variables
- High string-extraction volume typical of a bundled Node package
Reviewed 2026-09-28; recommended action: suppress false positive; model confidence 76%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace