Claude security directory

SAPUI5 MCP Server

Published by SAP SE

High risk

MCP server for SAPUI5/OpenUI5 development. Create and validate apps, access API docs, and get development guidelines.

Security assessment

Plutonium assessed this desktop extension for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.

Available capabilities

This add-on exposes 10 tools or capabilities.

  • get_guidelines
  • run_ui5_linter
  • get_api_reference
  • get_project_info
  • create_ui5_app
  • get_version_info
  • get_integration_cards_guidelines
  • create_integration_card
  • run_manifest_validation
  • get_typescript_conversion_guidelines

The interactive security report will load automatically.