Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add babamba2/superclaude-for-sap/plugin install sc4sapWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/babamba2/superclaude-for-sap/mcp-setup)<a href="https://agentmods.dev/skills/babamba2/superclaude-for-sap/mcp-setup"><img src="https://agentmods.dev/badge/skills/babamba2/superclaude-for-sap/mcp-setup/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/babamba2/superclaude-for-sap/mcp-setup"><img src="https://agentmods.dev/badge/skills/babamba2/superclaude-for-sap/mcp-setup.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00029 | $0.02079 |
| Opus 5 | $0.00015 | $0.01040 |
| Sonnet 5 | $0.00006 | $0.00416 |
| Haiku 4.5 | $0.00003 | $0.00208 |
Grade A, and why
sc4sap:mcp-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 144 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SC4SAP MCP Setup
Guides you through installing and configuring the abap-mcp-adt-powerup MCP server, which provides Claude Code with direct connectivity to your SAP system via ABAP Development Tools (ADT) REST APIs. The server exposes 150+ tools covering CRUD for ABAP objects (class, program, CDS, FM, table, etc.) plus runtime, transport, and data-preview operations.
<Response_Prefix>
Every response triggered by this skill MUST begin with [Model: <main-model> · Dispatched: <sub-summary>] per ../../common/model-routing-rule.md § Response Prefix Convention.
</Response_Prefix>
<Installation_Steps>
-
Automatic installation (recommended) The MCP server is automatically installed into the plugin's
vendor/abap-mcp-adt/directory during setup:/sc4sap:setup # full setup wizard (includes MCP install) /sc4sap:setup mcp # MCP install onlyOr via npm:
npm run build # runs tsc + installs abap-mcp-adt into vendor/This clones the repo, runs
npm install, and builds it. The plugin's.mcp.jsonis pre-configured to launchbridge/mcp-server.cjs, which delegates to the vendor-installed server. -
Configure SAP connection Create
.sc4sap/sap.envin the plugin directory with your SAP credentials:SAP_URL=https://your-sap-host:44300 SAP_CLIENT=100 SAP_AUTH_TYPE=basic SAP_USERNAME=your-user SAP_PASSWORD=your-password SAP_LANGUAGE=EN SAP_SYSTEM_TYPE=onprem TLS_REJECT_UNAUTHORIZED=0 # --- Blocklist policy (optional) --- # Controls the row-extraction guard in mcp-abap-adt. Defaults to `standard`. # minimal — block only PII/credentials/banking # standard — minimal + Protected Business Data (ACDOCA, BKPF, VBAK, EKKO, ...) [default] # strict — standard + Audit/Security + Communication/Workflow # off — disable the guard entirely (NOT recommended) # MCP_BLOCKLIST_PROFILE=standard # MCP_BLOCKLIST_EXTEND=ZHR_SALARY,ZCUSTOMER_PII # MCP_ALLOW_TABLE=ACDOCASAP_URL: SAP system URL with HTTPS and ICM port (typically 44300 for HTTPS)SAP_CLIENT: SAP client number (3 digits, e.g., "100")SAP_AUTH_TYPE:basicfor username/password,xsuaafor JWT (OAuth2)SAP_USERNAME/SAP_PASSWORD: SAP credentials with developer accessSAP_LANGUAGE: Logon language (EN, DE, etc.)SAP_SYSTEM_TYPE:onpremfor on-premise S/4HANA,cloudfor BTPTLS_REJECT_UNAUTHORIZED: Set to0for self-signed certificates (dev only)MCP_BLOCKLIST_PROFILE(optional):minimal|standard|strict|off— risk tier for row-extraction guard. Leave unset for the safe default (standard).MCP_BLOCKLIST_EXTEND(optional): comma-separated extra names/patterns (always denied). Use for site-specific Z-tables containing sensitive data.MCP_ALLOW_TABLE(optional): comma-separated whitelist for an audited one-off bypass. Logged to stderr. Remove when not actively needed.
The bridge reads this file automatically on startup. Environment variables take precedence over file values.
-
Verify the connection After restarting Claude Code (or reconnecting MCP via
/mcp), run:/sc4sap:sap-doctorOr manually test by calling
GetSession— it should return your SAP system ID, client, and username.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 144 lines · 29 tokens per session scan A 347e20c9e617
sc4sap:mcp-setup is a skill published in the GitHub repository babamba2/superclaude-for-sap (53 stars, last pushed 16d ago), licensed MIT. It adds 29 tokens to every session and 2,079 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…