Install
$ agentstack add skill-ilia-inovaflow-s4hana-create-record-skills-s4hana-create-service-entry-sheet ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
s4hana-create-service-entry-sheet
Create Service Entry Sheets on SAP S/4HANA Cloud Public (Lean Services). Verified end-to-end against SAP S/4HANA Cloud Public Edition 2026-05-12 — SES 1, 2, 3 posted via API.
Phase 0 — Setup check (MANDATORY, no exceptions)
Before any API call, before any tool use, do this check. Even if you already know credentials from earlier in the conversation — IGNORE that knowledge and re-check from scratch each invocation.
- Announce: tell the user "Checking for SAP credentials in ``..."
- Check ONLY these two sources:
- A
.envfile at./.env(in the current working directory — NOT parent dirs, NOT~/.env, NOT any memory file) - Shell-exported env vars:
SAP_HOSTANDSAP_AUTH_MODEboth present
- If neither: auto-create
./.envfrom the bundled template (curl fromhttps://raw.githubusercontent.com/ilia-inovaflow/s4hana-create-record-skills/main/.env.example), append.envto.gitignoreif not already there, tell the user clearly what to fill in (auth mode + host + creds), and wait for them to say "ready" before making any API call. Never overwrite an existing.env. - If credentials are present: report back to the user: "✓ Loaded credentials for `
in` mode. Proceeding with [task]."
Never use credentials from conversation memory, from another project's .env, or from any tenant the user previously worked with in a different session. Each project gets its own .env. See [shared/setup-check.md](../../shared/setup-check.md) for the full rationale and edge cases.
When to trigger
Verbs: create / post / add / generate / seed / enter / confirm Objects: SES, service entry sheet(s), service confirmation(s) Counts: 1 to ~50 records.
Hard rules (never violate)
- Always do a 1-record live POST as a probe before bulk (≥3 records).
- The referenced PO must be a SERVICE PO (cat
0+ SERV material + AAC=K). Uses4hana-create-powith the service-PO recipe first if none exist. - SES references the service line (cat 0), NOT the limit item (cat A) if the PO has one.
- Scripts go in
/.s4hana-tmp/create-ses-/. Never commit, never modify.env. - POSTs are sequential with 200ms delay; halt on 3 consecutive failures (but auto-retry once on
MM_PUR_SES/119: PO not releasedafter a 2-second wait — transient backend async).
Endpoint
- Service path:
/sap/opu/odata/sap/API_SERVICE_ENTRY_SHEET_SRV - Entity sets:
A_ServiceEntrySheet,A_ServiceEntrySheetItem,A_SrvcEntrShtAcctAssignment - Method: POST (deep-insert with
to_ServiceEntrySheetItem) - Communication scenario:
SAP_COM_0146— "Service Entry Sheet Integration" (must be added to comm user — common gap on fresh tenants)
There's also an OData V4 variant at /sap/opu/odata4/sap/api_serviceentrysheet/srvd_a2x/sap/serviceentrysheet/0001/ — same data, different protocol. Use V2 for now (this skill targets V2).
Phases
Phase 1 — Parse & gather input
For each SES, required:
| Field | Notes | |---|---| | PurchaseOrder (header + item) | A service PO that exists and is released | | PurchaseOrderItem (item) | The cat-0 service line on that PO (NOT cat-A limit line) | | ConfirmedQuantity | Amount of service performed (typically partial — 25%-100% of order qty) | | QuantityUnit | Match the PO line unit (e.g. AU) | | NetPriceAmount | Match the PO line price | | Plant, Currency | From the PO line | | PostingDate | Must be in open MM posting period (often different from FI periods — typically 2-3 months back) | | ServicePerformanceDate / EndDate | Must be within the PO line's allowed performance window — typically must equal or follow the PO creation date | | ServiceEntrySheetName | Free text, 40 char max |
If the user said "auto", pull eligible PO lines from A_PurchaseOrderItem?$filter=ProductType eq '2' and PurchaseOrderItemCategory eq '0' and IsFinallyInvoiced eq false.
Phase 2 — Preflight checks
Before bulk:
- Confirm the comm arrangement for
SAP_COM_0146is active (probeA_ServiceEntrySheet?$top=1— 403 HTML = missing arrangement). - Find an open MM posting period via either a probe (try to post with today's date, read M7/053 error for allowed periods) or
T_T001B-equivalent OData if accessible. Cache result. - For each candidate PO line, fetch performance window (
Item.NetPriceQuantity,Item.PurchaseOrderDateetc.) so SES dates are valid.
Phase 3 — Build payload
Minimal working envelope (verified):
{
"ServiceEntrySheetName": "",
"PurchaseOrder": "",
"PostingDate": "/Date()/",
"Currency": "EUR",
"to_ServiceEntrySheetItem": [
{
"ServiceEntrySheetItem": "10",
"PurchaseOrder": "",
"PurchaseOrderItem": "",
"ConfirmedQuantity": "",
"QuantityUnit": "AU",
"NetPriceAmount": "",
"Currency": "EUR",
"Plant": "1010",
"ServiceEntrySheetItemDesc": "",
"ServicePerformanceDate": "/Date()/",
"ServicePerformanceEndDate": "/Date()/"
}
]
}
Do NOT include to_AccountAssignment unless the user explicitly wants a different cost center than what's on the PO — SES auto-inherits the PO line's AAC/CostCenter/GLAccount, and explicit deep-insert often triggers MM_PUR_SES/128: accounting lines not numbered consecutively.
Phase 4 — CSRF + POST
Same CSRF flow as the other OData V2 services in this collection — see ../s4hana-create-po/references/csrf-flow.md.
If response is MM_PUR_SES/119: Purchase order X is not released. for a PO created in the same session/seconds ago → wait 2s and retry once (transient backend async). The PO IS released; the SES backend just hasn't refreshed its cache yet.
Phase 5 — Verify & report
After all POSTs, $expand=to_ServiceEntrySheetItem on 2-3 random SES to confirm. Show user: total created, SES ID range, supplier/PO distribution, any failures.
Output structure
/.s4hana-tmp/create-ses-/
├── eligible-po-lines.json # candidate POs after filtering
├── create-log.jsonl # one line per attempt
├── results.json # final summary
└── verify-sample.json
Reference files
references/envelope-template.md— full schema with all optional fieldsreferences/known-errors.md— error catalog (MMPURSES/006, /015, /119, /128, M7/053, etc.)references/po-not-released-retry.md— the transient async pattern + retry algorithmscripts/bulk-ses-poster.mjs— reference implementation
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ilia-inovaflow
- Source: ilia-inovaflow/s4hana-create-record-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.