abap-dev

abap-dev is a cursor rule for Cursor from engoetz/sap-adt-mcp. It costs 1,002 tokens per session, scanned A, original, Apache-2.0.

A set of instructions for developing ABAP, SAP's programming language, through SAP ADT tools connected to an IDE.

In plain words
What is it for?
Use it to search, read, edit, check, activate, and transport ABAP objects in a connected SAP system.
Why use it?
It explains how to connect to SAP systems safely and how to work with ABAP code without guessing which system or services are available.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/engoetz/sap-adt-mcp/abap-dev
Clone the repo
git clone --depth 1 https://github.com/engoetz/sap-adt-mcp

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for abap-dev

README.md
[![agentmods](https://agentmods.dev/badge/rules/engoetz/sap-adt-mcp/abap-dev.svg)](https://agentmods.dev/rules/engoetz/sap-adt-mcp/abap-dev)
Your own site
<a href="https://agentmods.dev/rules/engoetz/sap-adt-mcp/abap-dev"><img src="https://agentmods.dev/badge/rules/engoetz/sap-adt-mcp/abap-dev.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,002 This file is loaded in full into every session.
When invoked 1,002 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01002 $0.01002
Opus 5 $0.00501 $0.00501
Sonnet 5 $0.00200 $0.00200
Haiku 4.5 $0.00100 $0.00100

Measured 2d ago against content hash 62e2fafb4c2d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

abap-dev scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/abap-dev.mdc · 83 lines

How it starts

The opening of the file, as written. The whole thing — 83 lines — stays where its author put it; the contents beside it link to each section on GitHub.

ABAP Development via SAP ADT

You have access to SAP ADT MCP tools (server user-sap-adt in Cursor, key sap-adt in .cursor/mcp.json) that let you interact with the SAP ABAP system directly from Cursor.

Connection

  • Systems are not hardcoded here: call sap_list_environments to see what is configured on this machine, then connect to one of them.
  • Always call sap_connect before any SAP operation if not already connected.
  • Preferred: use sap_connect(system_id="<ID>") to load saved credentials from the OS credential manager.
  • If no saved credentials exist, tell the user to run sap-adt add <SYSTEM_ID> in the terminal — it prompts for the password without echoing it, keeping it out of the chat history. Only fall back to sap_save_password if they prefer to type it here.
  • Fallback: password can also come from SAP_PASSWORD environment variable.
  • On an unfamiliar or older system, run sap_system_info once after connecting: it lists which ADT endpoints exist there, so you know upfront whether activation, transports and syntax check work.
  • sap_disconnect ends the session when switching to another system.

Reading ABAP Code

  • Use sap_search with wildcards (e.g., Z*, ZCL_*) to find objects.
  • Use sap_read_source with the correct object_type:
    • PROG for programs/reports
    • PROG/I for includes
    • CLAS for classes
    • INTF for interfaces
    • FUGR for function groups
    • TABL, DTEL, DOMA, VIEW for DDIC objects
  • Other types (function modules, message classes, …) are resolved automatically via repository search; if that fails, pass source_uri directly (e.g. from sap_object_metadata).

Modifying ABAP Code

  • Always use sap_write_source — it handles locking, transport assignment, writing, activation, and unlocking in one call.
  • If the object is in a non-$TMP package, you must provide a transport_request.
  • If no transport is available, create one with sap_create_transport first.
  • Check lock status with sap_check_lock before attempting modifications.
  • If an object is locked by another user, do NOT attempt to modify it.

Read the full file on GitHub · 83 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 83 lines · 1,002 tokens per session scan A 62e2fafb4c2d

Subscribe to this mod's changes

abap-dev is a cursor rule published in the GitHub repository engoetz/sap-adt-mcp (0 stars, last pushed 8d ago), licensed Apache-2.0. It adds 1,002 tokens to every session, about $0.0050 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.