sap-api-policy-skill
Agent skill (npx skills) for evidence-based SAP API Policy alignment assessments — sourced, confidence-rated, never legal advice.
Install / Use
claude mcp add marianfoo -- npx -y github:marianfoo/sap-api-policy-skillIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
LegalSupported Platforms
Our assessment of sap-api-policy-skill
sap-api-policy-skill scores 74/100 on our quality scale, 34th of 51 Legal skills we index.
Its MCP Server is 4.5 KB long, well organised into 11 sections with 2 code examples: a solid amount of guidance for an agent.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
- Our last check on 2026-09-25 found the source still online.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 95/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
sap-api-policy-skill compared with similar skills
All 4 of these similar skills score higher than sap-api-policy-skill; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| sap-api-policy-skill (this skill)by marianfoo | 74 | 10 | 4mo ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 85.4k | 9d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 73.8k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.2k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.1k | 1d ago | CLAUDE.md |
Frequently asked questions
- How do I install sap-api-policy-skill?
- Run
claude mcp add marianfoo -- npx -y github:marianfoo/sap-api-policy-skill. The install tabs above show the steps for each supported agent. - Which AI agents does sap-api-policy-skill work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is sap-api-policy-skill safe to use?
- It is MIT-licensed and scores 95/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is sap-api-policy-skill still maintained?
- The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
Skill content
View source on GitHubSAP API Policy Evidence Skill
An agent skill that assesses whether a given SAP API usage scenario aligns with the SAP API Policy (v.4.2026a + FAQ) and returns an evidence-based, sourced technical assessment with a confidence level — by gathering live evidence from official SAP sources (SAP Help, Business Accelerator Hub, SAP Notes, Architecture Center, released-object data) via MCP servers.
Not legal advice, not a final SAP compliance decision. Only SAP, your contract, or SAP support/account/legal can give a binding answer. This skill gets as close as the evidence allows, labels its confidence, and routes legal/commercial/roadmap questions to SAP rather than answering them.
Install
Cross-agent via the skills CLI (works with Claude Code,
Cursor, Codex, and others):
# install just this skill (use your own owner/repo if you fork it)
npx skills add marianfoo/sap-api-policy-skill --skill sap-api-policy-evidence
# or install everything in the repo
npx skills add marianfoo/sap-api-policy-skill
# globally, across all projects
npx skills add -g marianfoo/sap-api-policy-skill --skill sap-api-policy-evidence
Manual install (no CLI): copy skills/sap-api-policy-evidence/ into your agent's skills directory
(e.g. ~/.claude/skills/ for Claude Code) — see MCP_SETUP.md → "Using the skill".
Prerequisite: the SAP MCP servers
The skill gathers evidence through SAP MCP servers — set them up once (most are npx-installable, SAP
Docs has a hosted URL):
| Server | Install | Role |
| --- | --- | --- |
| SAP Docs | hosted URL or mcp-sap-docs | SAP Help, Architecture Center, released-object status |
| SAP API Hub | npx -y sap-api-hub-mcp | prove Published-API status / version / specs |
| SAP Notes | sap-note-search-mcp (node) | "not permitted" / deprecated / successor notes |
| SAP Roadmap | npx -y sap-roadmap-mcp | future replacement APIs (planning only) |
| ARC-1 | npx -y arc-1@latest | live-system release state / custom-API checks |
The three authenticated servers (API Hub, Roadmap, Notes) and their shared SAP login module live in
one repo — sap-mcp-servers (npm workspaces) — but
each is still published to npm individually, so the npx -y forms above work as-is.
Full setup (auth, MFA, portable config, per-client usage): MCP_SETUP.md. The skill
degrades gracefully if some are missing and says which were unavailable; SAP API Hub + an
authenticated SAP Notes session are what let assessments reach high confidence.
What it covers
Published-API vs internal/private status · "Documented Use" · third-party tools / iPaaS / RPA · agentic & generative-AI / MCP access · bulk extraction & replication · custom Z/Y OData & RFC/BAPI wrappers & Clean Core · ADT developer-tooling boundaries (FAQ Q33) · ODP-RFC and other "not permitted" interfaces · partner Integration Certification · RISE remediation · an inventory/scan mode ("which of these APIs are allowed?").
Example prompts
- Decisive: "Is it allowed under SAP's API policy to extract data from our BW/4HANA into Snowflake nightly via ODP-RFC through a third-party ETL tool?"
- Should be aligned: "We sync ~500 Shopify orders/day into S/4HANA Cloud via the standard Sales Order OData API using Boomi — OK under the 2026 API policy?"
- Scan a list: "Which of these are OK to keep using: API_SALES_ORDER_SRV, RFC_READ_TABLE, SD_SALESDOCUMENT_CREATE, ODP-RFC, I_SalesDocument?"
Repo layout
skills/sap-api-policy-evidence/ the skill — SKILL.md + references/ + agents/openai.yaml
evals/evals.json 22 scenario evals (the test suite)
tests/skill_static_checks.py contract checks (fixed labels, required refs, URLs)
MCP_SETUP.md MCP server setup + how to consume the skill
CLAUDE.md contributor/maintainer guide (how to edit + validate the skill)
.cursor/mcp.json.example portable MCP client config — copy to .cursor/mcp.json and fill in
Validation
The skill was hardened over 6 eval iterations across 22 scenarios spanning every policy branch plus
adversarial over/under-flag, legal-wall, and scan-mode probes. It returns a fixed verdict label
(Likely aligned / Likely not aligned / Needs SAP confirmation / Not assessable from provided facts), a single confidence level, cited sources, and the non-legal disclaimer.
License
MIT — see LICENSE.
Related Skills
Agent-Reach
85.4kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
73.8kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.2k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.1kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
