ARC-1
NPM · ARC-1 · 2 COMPONENTS · SCANNED SEP 20
MCP server for SAP ABAP systems
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 90 of 216 dependencies flagged as unhealthy (1 deprecated). View diagnostics → Partial
Provenance & Transparency74
- Repository check failed: the declared repository URL redirects; it must resolve directly. See how to fix → View diagnostics → Fail
- Cryptographically verified build provenance (signed, bound to marianfoo/arc-1). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 2 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability56
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 8504 tokens (~1063/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the ARC-1 MCP server?
ARC-1 runs locally as an npm package, launched with npx -y arc-1. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · arc-1
claude mcp add marianfoo-arc-1 -- npx -y arc-1
{
"mcpServers": {
"marianfoo-arc-1": {
"command": "npx",
"args": [
"-y",
"arc-1"
]
}
}
} {
"servers": {
"marianfoo-arc-1": {
"command": "npx",
"args": [
"-y",
"arc-1"
]
}
}
} codex mcp add marianfoo-arc-1 -- npx -y arc-1
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"marianfoo-arc-1": {
"type": "local",
"command": [
"npx",
"-y",
"arc-1"
],
"enabled": true
}
}
} openclaw mcp add marianfoo-arc-1 --command npx --arg -y --arg arc-1
mcp_servers:
marianfoo-arc-1:
command: "npx"
args: ["-y", "arc-1"] {
"McpServers": {
"marianfoo-arc-1": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"arc-1"
]
}
}
} assistant mcp add marianfoo-arc-1 -t stdio -c npx -a -y arc-1
{
"mcpServers": {
"marianfoo-arc-1": {
"command": "npx",
"args": [
"-y",
"arc-1"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 −3
- Stability: pass → 0.80 functional
- 19 Sept 26 0
- Stability: 0.97 → pass security
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 −3
- Stability: pass → 0.77 functional
- 11 Sept 26 0
- Stability: 0.97 → pass security
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/arc-1@0.9.18
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | marianfoo/arc-1 |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/marianfoo/arc-1/.github/workflows/release.yml@refs/heads/main |
| Rekor log index | 1839808092 |
| Predicate type | https://slsa.dev/provenance/v1 |
| Subject digest | sha512:e1b0be5f85d385173fe53fa29155adfce01e12f39a4b829465548ef8074f122f568eb1629736caf9e43edaa602071f9efea9d416dc63b353555d2beb2 |
Background: How many MCP packages publish verified provenance →
Dependencies 216 packages
| Packages resolved | 216 |
|---|---|
| Deprecated | 1 |
| Stale | 87 |
| No linked repository | 2 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
SAPContext ~1,136
Get compressed dependency context or CDS blast-radius impact for an ABAP / CDS object. Decision rule — pick the action based on the user's question: - "What breaks if I change <CDS view>?" / "Who consumes <I_*>?" / "Impact analysis on <DDLS>" / "Blast radius" → action="impact" - "Understand dependencies before editing <object>" / "What does X depend on?" → action="deps" (default) - "Find all callers of <object>" (cache-warmup required) → action="usages" action="impact" (CDS blast-radius, DDLS only): ALWAYS use this for CDS change-impact questions. Returns upstream AST dependencies plus downstream where-used results classified into RAP-aware buckets: projectionViews, bdefs, serviceDefinitions, serviceBindings, accessControls (DCLS), metadataExtensions (DDLX), abapConsumers, documentation (SKTD), tables, other. Also emits additive sibling-consistency diagnostics (consistencyHints + siblingExtensionAnalysis) when sibling DDLS variants in the same package show asymmetric metadata-extension coverage. DO NOT replicate this with SAPQuery against DDDDLSRC/ACMDCLSRC/DDLXSRC_SRC/SRVDSRC_SRC — those text scans produce noise (non-dependency matches, package group nodes) that this classifier already filters out. Optional includeIndirect=true widens to transitive consumers. Optional siblingCheck=false disables sibling analysis; siblingMaxCandidates controls fan-out (default 4, hard cap 10). action="deps" (default): Returns only the public API contracts (method signatures, interface definitions, type declarations) of all objects that the target depends on — NOT the full source code. The most token-efficient way to understand dependencies. Instead of N separate SAPRead calls returning full source (~200 lines each), returns ONE response with compressed contracts (~15-30 lines each). Typical compression: 7-30x fewer tokens. What deps extracts per dependency: - Classes: CLASS DEFINITION with PUBLIC SECTION only (methods, types, constants). PROTECTED, PRIVATE and IMPLEMENTATION st…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | Action: "impact" = CDS blast-radius analysis (DDLS only). USE THIS for any question like "what breaks if I change <view>", "who consumes <I_*>", "impact analysis on <CDS>", "downstream of <view>". Re… |
| depth | number | – | Dependency depth: 1 = direct deps only (default), 2 = deps of deps, 3 = maximum. Higher depth = more context but more SAP calls. |
| group | string | – | Required for FUNC type. The function group containing the function module. |
| includeIndirect | boolean | – | Only for action="impact". Include indirect (transitive) downstream where-used entries. Default false. |
| maxDeps | number | – | Maximum dependencies to resolve (default 20). Lower = faster + fewer tokens. |
| name | string | yes | Object name (e.g., ZCL_ORDER) |
| siblingCheck | boolean | – | Only for action="impact". Enable sibling metadata-extension consistency analysis. Default true. |
| siblingMaxCandidates | number | – | Only for action="impact". Maximum sibling DDLS candidates to compare. Default 4; hard cap 10. |
| source | string | – | Optional: provide source directly instead of fetching from SAP. Saves one round-trip if you already have the source from SAPRead. |
| type | string | – | Object type. Required for action="deps" and action="usages". Optional for action="impact" — defaults to DDLS (the only supported type for impact). |
No output schema declared.
No examples provided.
SAPDiagnose ~1,226
Run diagnostics on ABAP objects and analyze runtime errors. Actions: - "syntax": Syntax check an ABAP object. Requires name + type. Optional: version ("active" or "inactive", defaults to active). Optional: source — when supplied, SAP compiles the given content as if it lived at the object's URI (pre-write dry-run, nothing is written). Omit source to check what is stored. - "unittest": Run ABAP unit tests. Requires name + type. - "atc": Run ATC code quality checks. Requires name + type. Optional: variant. - "cds_testcases": Get SAP-suggested ABAP Unit test cases for a CDS entity (CDS Test Double Framework). Requires name (the CDS entity / DDLS source name; no type needed). Returns one test-method suggestion per testable semantic (whole view, calculated fields, CAST/JOIN/CASE) to scaffold a cl_cds_test_environment unit test. Read-only; SAP_BASIS 8.16+ (ABAP Platform 2025 / S/4HANA 2025) only. - "object_state": Compare active and inactive source versions. Requires name + type. For CLAS, also compares main, definitions, implementations, macros, and testclasses includes (up to 10 parallel reads per class; sequence calls when sweeping many classes). Returns ETags, byte lengths, hashes, and divergence flags. - "quickfix": Get SAP quick fix proposals for a specific source position. Requires name + type + source + line. Optional: column, sourceUri for exact ADT include/source targets. - "apply_quickfix": Apply one quick fix proposal and return text deltas (does not write source). Requires name + type + source + line + proposalUri + proposalUserContent. Optional: column, sourceUri, proposalAffectedObjects. proposalUserContent may be an empty string; pass it through exactly from quickfix. - "dumps": List or read ABAP short dumps (ST22). Without id: lists recent dumps (filter by user, maxResults). With id: returns focused chapter sections by default; set includeFullText=true to include the full formatted dump blob. Optional sections=[kap0,kap3,...] to request specific chapter…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Diagnostic action |
| analysis | string | – | Trace analysis type (for traces action with id). hitlist = execution hot spots, statements = call tree, dbAccesses = database access stats. |
| column | number | – | Source column number for quickfix evaluation (default 0 for quickfix actions). |
| detailUrl | string | – | ADT detail URL for gateway_errors detail mode (preferred over id+errorType). Accepts absolute or /sap/bc/adt/... path. |
| errorType | string | – | Gateway error type for gateway_errors detail by id (for example "Frontend Error"). Required when using id without detailUrl. |
| from | string | – | Optional lower time boundary for feed-based diagnostics actions (system_messages/gateway_errors). |
| id | string | – | Dump or trace ID (for dumps/traces actions). Omit to list, provide to get details. |
| includeFullText | boolean | – | For dumps detail mode only: include full formattedText blob. Default false to reduce token usage. |
| line | number | – | Source line number for quickfix evaluation (required for quickfix/apply_quickfix). |
| maxResults | number | – | Maximum results to return for dumps/system_messages/gateway_errors (default 50, bounded to a safe cap). |
| name | string | – | Object name (for syntax/unittest/atc/object_state); the CDS entity / DDLS source name for cds_testcases |
| proposalAffectedObjects | array | – | Optional affectedObjects array from quickfix action. Include content for each affected source unit when applying multi-object quickfixes. |
| proposalUri | string | – | Quickfix proposal URI from quickfix action (required for apply_quickfix). |
| proposalUserContent | string | – | Opaque userContent from quickfix action (required for apply_quickfix). May be an empty string; pass through exactly. |
| sections | array | – | Dump chapter IDs to include for dumps detail mode (for example ["kap0","kap3","kap8"]). Omit to use focused defaults. |
| source | string | – | Current source code (required for quickfix/apply_quickfix). |
| sourceUri | string | – | Exact ADT source URI for quickfix/apply_quickfix. Defaults to the type/name main source; use this for class includes such as /includes/definitions. |
| to | string | – | Optional upper time boundary for feed-based diagnostics actions (system_messages/gateway_errors). |
| type | string | – | Object type (PROG, CLAS, etc.) (for syntax/unittest/atc/object_state) |
| user | string | – | Filter dumps by SAP user (for dumps action) |
| variant | string | – | ATC check variant (for atc action) |
| version | string | – | Source version for syntax check (default "active"). Use "inactive" to validate pending changes. |
No output schema declared.
No examples provided.
SAPLint ~405
Run local abaplint rules on ABAP and CDS source code. System-aware: auto-selects cloud or on-prem rules based on detected system type. Actions: - "lint": Check source for issues. Returns errors and warnings. Works for ABAP (PROG, CLAS, INTF, FUNC) and CDS views (DDLS) — catches syntax errors, naming conventions, field order, legacy view patterns. - "lint_and_fix": Lint + auto-fix all fixable issues (keyword case, obsolete statements, etc.). Returns fixed source. - "list_rules": List all available rules with current config. No source needed. - "format": Pretty-print ABAP source via SAP's ADT formatter (uses the SAP system's global formatter settings). Requires source. Returns the formatted source. - "get_formatter_settings": Read the SAP system's global PrettyPrinter settings (indentation, keyword style). No params. - "set_formatter_settings": Update the SAP system's global PrettyPrinter settings. Requires indentation (bool) and/or style (keywordUpper|keywordLower|keywordAuto|none). Blocked in read-only mode. For server-side checks (ATC, syntax check, unit tests), use SAPDiagnose instead. Note: lint/lint_and_fix/list_rules run locally; format/*_formatter_settings call the SAP system.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Check type |
| indentation | boolean | – | PrettyPrinter: indent source (for set_formatter_settings) |
| name | string | – | Object name (used for filename detection) |
| rules | object | – | Rule overrides: { "rule_name": false } to disable, { "rule_name": { "severity": "Warning" } } to configure. Overrides system defaults. |
| source | string | – | ABAP or CDS source code to lint/format (not needed for list_rules/get_formatter_settings) |
| style | string | – | PrettyPrinter: keyword casing (for set_formatter_settings) |
No output schema declared.
No examples provided.
SAPManage ~930
Probe and report SAP system capabilities. Use this BEFORE attempting operations that depend on optional features (abapGit, RAP/CDS, AMDP, HANA, UI5/Fiori, CTS transports, FLP customization). Also handles package (DEVC) lifecycle operations. Actions: - "features": Get cached feature status from last probe (fast, no SAP round-trip). Returns which features are available, their mode (auto/on/off), and when they were last probed. - "probe": Re-probe the SAP system now (runs feature probes, auth checks, and ADT discovery refresh). Use this on first use or if you suspect feature availability has changed. - "cache_stats": Show object cache health and warmup state. - "flp_list_catalogs": List FLP business catalogs. - "flp_list_groups": List FLP groups. - "flp_list_tiles": List tiles in a catalog (requires "catalogId"). - "create_package": Create a package (DEVC) via ADT packages API. - "delete_package": Delete an existing package. - "flp_create_catalog": Create a business catalog (requires "domainId", "title"). - "flp_create_group": Create a group (requires "groupId", "title"). - "flp_create_tile": Create a tile in a catalog (requires "catalogId", "tile"). - "flp_add_tile_to_group": Add a catalog tile to a group (requires "groupId", "catalogId", "tileInstanceId"). - "flp_delete_catalog": Delete a business catalog (requires "catalogId"). Returns JSON with features, each having: id, available (bool), mode, message, and probedAt timestamp. Also returns systemType ("btp" or "onprem") for understanding available capabilities. "available: false" means do NOT attempt operations that depend on it.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Action to execute. Read actions: features, probe, cache_stats, flp_list_catalogs, flp_list_groups, flp_list_tiles. Mutating package/FLP actions require writable safety config and write scope in authe… |
| catalogId | string | – | FLP catalog identifier — accepts either full ID (X-SAP-UI2-CATALOGPAGE:MY_CAT) or domain ID (MY_CAT). Required for flp_list_tiles, flp_create_tile, flp_add_tile_to_group, flp_delete_catalog. |
| description | string | – | Package description (required for create_package). |
| domainId | string | – | Domain ID for FLP catalog creation (e.g., ZARC1_SALES). |
| groupId | string | – | FLP group/page identifier (required for flp_create_group, flp_add_tile_to_group). |
| name | string | – | Package name (required for create_package and delete_package). |
| newPackage | string | – | Target package to move the object to. Required for change_package. |
| objectName | string | – | Object name to move (e.g., ZCL_MY_CLASS). Required for change_package. |
| objectType | string | – | ADT object type (e.g., CLAS/OC, DDLS/DF, PROG/P). Required for change_package. |
| objectUri | string | – | ADT URI of the object to move (e.g., /sap/bc/adt/oo/classes/zcl_my_class). If not provided, resolved automatically from objectName + objectType via search. |
| oldPackage | string | – | Current package of the object. Required for change_package. |
| packageType | string | – | Package type for create_package (default: development). |
| recordChanges | boolean | – | Whether the created package records object changes in transport requests. Defaults to true for non-LOCAL software components or when a transport layer is set; false for literal LOCAL packages. |
| softwareComponent | string | – | Software component for create_package (default: LOCAL). |
| superPackage | string | – | Parent package for create_package (defaults to empty root package). |
| tile | object | – | Tile definition for flp_create_tile. |
| tileInstanceId | string | – | Tile instance ID in the source catalog (required for flp_add_tile_to_group). |
| title | string | – | Title for FLP catalog/group creation. |
| transport | string | – | Optional transport request (corrNr) for create_package, delete_package, or change_package. |
| transportLayer | string | – | Transport layer for create_package (optional; required by some transportable landscapes). |
No output schema declared.
No examples provided.
SAPNavigate ~442
Navigate code: find definitions, references (where-used), code completion, and class hierarchy. Use for "go to definition", "where is this used?", "what does this class inherit?", and auto-complete. For references: uses the full scope-based Where-Used API returning detailed results with line numbers, snippets, and package info. Optional objectType filter narrows results to a specific ADT type in slash format (e.g., CLAS/OC, PROG/P). Type+name params are auto-normalized (e.g., type="clas" works). For hierarchy: returns superclass, implemented interfaces, and direct subclasses via SEOMETAREL. You can use type+name instead of uri (e.g., type="CLAS", name="ZCL_ORDER") for a where-used list without needing the full ADT URI. For CDS entities (DDLS), prefer SAPContext(action="impact") — it returns the same where-used data pre-classified into RAP buckets (projection views, BDEFs, SRVDs, access controls, metadata extensions, documentation, ABAP consumers), which answers "what breaks if I change this view" directly without manual bucketing.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Navigation action |
| column | number | – | Column number (1-based) |
| line | number | – | Line number (1-based) |
| name | string | – | Object name — alternative to uri for references. |
| objectType | string | – | For references action: filter where-used results by ADT object type in slash format (e.g., PROG/P, CLAS/OC, FUGR/FF, INTF/OI). On systems supporting the scope endpoint, only returns references from o… |
| source | string | – | Current source code (for definition/completion) |
| type | string | – | Object type (PROG, CLAS, INTF, FUNC, etc.) — alternative to uri for references. |
| uri | string | – | Source URI of the object. Optional for references if type+name are provided. |
No output schema declared.
No examples provided.
SAPRead ~2,524
Read SAP ABAP objects. Types: PROG, CLAS, INTF, FUNC, FUGR (use expand_includes=true to get all include sources), INCL, DDLS, DCLS (CDS access controls), DDLX (CDS metadata extensions — UI annotations), BDEF, SRVD, SRVB (service bindings — returns structured binding info: OData version, publish status, service definition ref), SKTD (Knowledge Transfer Documents — Markdown documentation attached to ABAP objects like CDS views, BDEFs, classes), TABL (DDIC TABL — covers transparent tables like T000 AND DDIC structures like BAPIRET2; returns CDS-like source. ARC-1 auto-resolves the URL: tries /sap/bc/adt/ddic/tables/ first, falls back to /sap/bc/adt/ddic/structures/. Note: there is no separate STRU type — TABL is the canonical short type for both, mirroring TADIR R3TR TABL and abapGit conventions), VIEW, DOMA (DDIC domains — returns type info, value table, fixed values), DTEL (data elements — returns domain, labels, search help), TRAN (transaction codes — returns description, program, package), TABLE_CONTENTS (simple row preview — no filter or single-column filter; use TABLE_QUERY for multi-column WHERE), TABLE_QUERY (structured multi-column query on DDIC tables and CDS views via the freestyle endpoint — supports AND conditions, column selection; gated by allowDataPreview; use instead of TABLE_CONTENTS when filtering on multiple fields. Note: CDS views require SAP_BASIS 752+ — NW 7.50/7.51 rejects them with "TABLE is invalid here"), DEVC, SOBJ (BOR business objects — returns method catalog or full implementation), SYSTEM, COMPONENTS, MSAG (message classes — returns class metadata + messages array), TEXT_ELEMENTS, VARIANTS. For CLAS: omit include to get the full class source (definition + implementation combined). The include param is optional — use it only to read class-local sections: definitions (local types), implementations (local helper classes), macros, testclasses (ABAP Unit). For CLAS with method param: use method="*" to list all methods with signatures and vis…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | Set to "diff" for a unified diff between two source versions (uses from/to) — cheaper than fetching both sources. Source types only: PROG, CLAS, INTF, FUNC, FUGR, INCL, DDLS, DCLS, BDEF, SRVD, DDLX,… |
| columns | array | – | For TABLE_QUERY: columns to SELECT (default: all). Example: ["MATNR","BWART","BUDAT","MENGE"]. |
| expand_includes | boolean | – | For FUGR type only. When true, recursively expands the function group include tree — the main source plus all nested INCLUDEs (the FUNCTION...ENDFUNCTION bodies live in nested LZ<grp>U01/U02 includes… |
| force_refresh | boolean | – | For source reads: bypass cached source and inactive-list state before reading. Use when you know the object changed outside ARC-1. |
| format | string | – | Output format. "text" (default): raw source code. "structured" (CLAS only): JSON with metadata (description, language, category) + decomposed source (main, testclasses, definitions, implementations,… |
| from | string | – | action="diff" OLD side: "active" (default), "inactive", a revision id from SAPRead(type="VERSIONS"), or a /sap/bc/adt/ revision URI. |
| grep | string | – | Regex pattern (case-insensitive) to search within the object source. Returns only matching lines with 1-based line numbers and ±3 context lines, instead of the full source — token-efficient. For CLAS… |
| group | string | – | For FUNC/VERSIONS type. The function group containing the function module. Optional for FUNC — auto-resolved via SAPSearch if omitted. Required for VERSIONS when querying a function module revision f… |
| include | string | – | For CLAS: DO NOT use this to read the main class — omit include entirely to get the full class source (CLASS DEFINITION + CLASS IMPLEMENTATION). This parameter reads class-LOCAL auxiliary files only:… |
| includeSignature | boolean | – | For FUNC type only. When true, response is JSON: {source, signature: {importing[], exporting[], changing[], tables[], exceptions[], raising[]}} — each parameter parsed into {kind, name, type, byValue… |
| maxResults | number | – | For DEVC: max number of objects to list (default 200, clamped to [1, 1000]). Larger packages may be silently truncated by SAP at this limit; raise it if needed. |
| maxRows | number | – | For TABLE_CONTENTS and TABLE_QUERY: max rows to return (default 100) |
| method | string | – | For CLAS: method name to read a single method implementation (e.g., "get_name", "zif_order~process"). Use "*" to list all methods with signatures and visibility. For SOBJ: BOR method name to read. If… |
| name | string | – | Object name (e.g., ZTEST_PROGRAM, ZCL_ORDER, MARA) |
| objectType | string | – | For API_STATE and VERSIONS: SAP object type (CLAS, INTF, PROG, FUNC, INCL, DDLS, DCLS, BDEF, SRVD, etc.). For API_STATE: auto-detected from name if omitted. For VERSIONS: required to pick the correct… |
| sqlFilter | string | – | For TABLE_CONTENTS: condition expression only (no WHERE, no SELECT), e.g. "MANDT = '100'" or "MATNR LIKE 'Z%'". |
| to | string | – | action="diff" NEW side (default "inactive" = pending unactivated changes). Same values as from. |
| type | string | yes | Object type to read (on-prem): PROG, CLAS, INTF, FUNC, FUGR, INCL, DDLS, DCLS, DDLX, BDEF, SRVD, SRVB, SKTD, TABL (transparent tables and DDIC structures), VIEW, DOMA, DTEL, MSAG, TRAN, TABLE_CONTENT… |
| version | string | – | Source version to read. "active" (default) returns the last activated version. "inactive" returns the user's unactivated draft or active if no draft exists. "auto" returns the draft if one exists, el… |
| versionUri | string | – | For VERSION_SOURCE: URI of a specific revision from SAPRead(type="VERSIONS") response (.revisions[].uri). Must start with /sap/bc/adt/. |
| where | array | – | For TABLE_QUERY: structured WHERE conditions, ANDed together. Each item: {field, op, value?}. Allowed ops: =, !=, <>, <, <=, >, >=, LIKE, NOT LIKE, IN, NOT IN, IS NULL, IS NOT NULL. For IN/NOT IN: va… |
No output schema declared.
No examples provided.
SAPSearch ~527
Search for ABAP objects. Search by name pattern with wildcards (* for any characters). Returns object type, name, package, description, and ADT URI. Use this to find classes, programs, function modules, tables, etc. 2. TADIR lookup (searchType="tadir_lookup"): Exact cross-package object lookup for one or more names via ADT repository quick search. Use this before create/reset workflows instead of long SAPQuery TADIR IN-lists. Tips: BOR business objects appear as SOBJ type in results. The uri field from results can be used directly with SAPNavigate for references. The objectType field from results can be passed directly to SAPRead/SAPWrite/SAPActivate (ARC-1 auto-normalizes slash suffixes like DDLS/DF, CLAS/OC, PROG/P). Note: Searches object names only (classes, tables, CDS views, etc.) — field/column names are not searchable here. To find fields by name, use SAPRead(type='DDLS', include='elements') for CDS views or SAPQuery against DD03L.
| Name | Type | Req | Description |
|---|---|---|---|
| maxResults | number | – | Maximum results (default 100) |
| names | array | – | For tadir_lookup: exact object names to resolve across packages. Prefer this over long SAPQuery TADIR IN-lists. |
| objectType | string | – | For source_code search: filter by object type (e.g., PROG, CLAS, FUNC). For tadir_lookup: single type filter; use objectTypes for multiple. |
| objectTypes | array | – | For tadir_lookup: optional ADT/TADIR type filters (e.g., TABL, DDLS, BDEF, SRVB, CLAS/OC). |
| query | string | – | Search pattern for object search, or comma/whitespace-separated names for tadir_lookup. |
| searchType | string | – | Search mode: "object" (default) searches by object name, "tadir_lookup" does exact cross-package object lookup. |
| source | string | – | For tadir_lookup only: data source for the lookup. "adt" (default) uses the ADT info-system endpoint — workbench-resolvable objects only. "db" issues SQL against table TADIR — also surfaces orphan/gh… |
No output schema declared.
No examples provided.
SAPTransport ~1,314
Manage CTS transport requests (SE09/SE10 equivalent). Actions: list (defaults to current user, modifiable transports — both Workbench and Customizing), get (details with tasks and objects), create (K=Workbench, W=Customizing, T=Transport of Copies), release, delete, remove_object (remove an object, keep the request), reassign (change owner), release_recursive (release tasks first, then parent), check (check if a package requires a transport — provide type, name, package), history (find transports referencing an object — provide type, name; read-only, works without SAP_ALLOW_TRANSPORT_WRITES). Transport IDs look like A4HK900123. Status: D=modifiable, R=released.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | list: show transports (defaults to current user, modifiable only). Pass summary=true for a headers-only overview that omits each transport's object lists (keeps an objectCount) — far cheaper when man… |
| description | string | – | Transport description text (required for create) |
| id | string | – | Transport request ID, e.g. A4HK900123 (required for get/release/delete/reassign/release_recursive/remove_object) |
| name | string | – | Object name (for check, history, or remove_object actions) |
| owner | string | – | New owner SAP username (required for reassign) |
| package | string | – | Package name. For create: optional — defaults to $TMP, pass an explicit package to influence the transport route (SAP infers K/W/T from the package's TADIR route). For check: required. |
| pgmid | string | – | Program ID for remove_object: "R3TR" (whole object) or "LIMU" (sub-object). Required — object type alone does not determine pgmid. |
| recursive | boolean | – | Apply recursively to child tasks (for delete/reassign). release_recursive always recurses. |
| removeLockedObjects | boolean | – | For delete only. Strip locked objects from each task before deleting, so a request that still holds a locked object (e.g. a deleted object's lingering record → HTTP 400 "...contains locked objects")… |
| status | string | – | Transport status filter (for list). D=modifiable (default), R=released, "*"=all statuses. |
| summary | boolean | – | For list only. Headers-only overview: omit each transport's (and task's) object lists, keeping id/description/owner/status/target plus an objectCount. Use it to scan many open transports cheaply, the… |
| target | string | – | Explicit transport target (Transportziel / TR_TARGET) for create — what the user means by "create a transport with target X". Forms: a system ("C11"), system.client ("C11.021"), or target group ("/TR… |
| transportLayer | string | – | Transport layer for create (optional, advanced). Sent as the ?transportLayer= query param to override which consolidation route — and therefore which target — SAP resolves. OMIT IT by default: SAP re… |
| type | string | – | Object type for check/history/remove_object actions (PROG, CLAS, DDLS, etc.). Not used by create — the SAP backend infers transport type (K/W/T) from the package's TADIR route on the CreateCorrection… |
| user | string | – | SAP username to filter by (for list). Defaults to the current SAP user. Use "*" to list all users. |
No output schema declared.
No examples provided.
What is the ARC-1 MCP server?
ARC-1 is an MCP server listed in the public MCP registry as io.github.marianfoo/arc-1. MCP server for SAP ABAP systems. This page covers its npm package (arc-1).
Is the ARC-1 MCP server safe to use?
ARC-1 scores 83 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the ARC-1 MCP server expose?
ARC-1 exposes 8 tools: SAPRead, SAPSearch, SAPNavigate, SAPLint, SAPDiagnose, and 3 more. Their descriptions and schemas cost roughly 8,504 tokens of context every time the server is loaded.
Is the ARC-1 MCP server still maintained?
ARC-1 is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the ARC-1 MCP server under?
ARC-1 declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.