Atlas / MCP servers / 7xuanlu / Wenlan

WenlanBLOCK

mcp/7xuanlu/wenlan

A living personal wiki. Wenlan turns your documents, notes, and AI chats into pages with links to their sources, and updates them as sources change without overwriting your edits. Claude Code, Codex and other AI tools can build on it.

Verdict
BLOCK
Grade
F
Trust score
35 /100
Exposed tools
17 17r · 0w · 0d
Transport
streamable-http
License
Apache-2.0
Stars
79
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Wenlan turns your documents, notes, and AI conversations into editable pages with links to their sources, so you and your AI tools can keep building on them.

As sources change, you can ask AI to update the pages or enable background updates. If you’ve edited a page, Wenlan proposes revisions for you to review instead of automatically overwriting your work.

English | 简体中文 | 繁體中文 | Español

Get started · What is this? · Capabilities · Daily workflow · Evaluation · Learn more

https://github.com/user-attachments/assets/35f06749-00e5-484d-a9f4-5e462de8d11e

The opening frame is a composed preview, not a native three-pane view. The rest shows the app in use, including pages and source citations.

Read from source at commit a5e731757643OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add wenlan-readme-visuals --env CARGO_REGISTRY_TOKEN=${CARGO_REGISTRY_TOKEN} --env GH_TOKEN=${GH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env WENLAN_REQUIRE_AUTHENTICODE=${WENLAN_REQUIRE_AUTHENTICODE} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "wenlan-readme-visuals": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CARGO_REGISTRY_TOKEN": "${CARGO_REGISTRY_TOKEN}",
        "GH_TOKEN": "${GH_TOKEN}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}",
        "WENLAN_REQUIRE_AUTHENTICODE": "${WENLAN_REQUIRE_AUTHENTICODE}"
      }
    }
  }
}
03

Exposed tools (17)

17 read · 0 write · 0 destructive.

ToolRiskDescription
ArchivereadOlder material
HealthreadFitness
OriginreadA working context
PersonalreadDurable preferences
ResearchreadPrimary-source investigations
SuggestedreadSuggested description
WenlanreadNotes and references for a simpler writing experience.
WorkreadClient projects
careerreadCareer stuff
confirmed_vs_unconfirmedreadConfirmed relevant memory competing with unconfirmed negative at similar embedding distance
cross_domain_semantic_overlapreadTechnical query where identity/personal memories share keywords with project-specific decisions
fts_and_failurereadMulti-word query where relevant memory doesn
graph_observation_vs_memoryreadKnowledge graph observations competing with direct memories for the same query
recap_original_competitionreadOriginal memory competing with its recap summary that has high keyword overlap
structured_vs_prosereadMemory with structured_fields vs plain prose memory for the same query
workreadWork stuff
讀書會read一起閱讀,留下自己的理解。
04

Trust audit

BLOCKgrade F · trust 35/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (13 observation(s))
Network
declared (14 observation(s))
Shell
declared (9 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
crates/wenlan-core/src/quality_gate.rs:784
"Use this token ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijkl for GitHub access",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
crates/wenlan-core/src/quality_gate.rs:1197
("Use token ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij to access the private repository resources", "credential"),
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/wenlan-core/src/privacy.rs:93
"-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQ...\n-----END RSA PRIVATE KEY-----";
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
crates/wenlan-core/src/quality_gate.rs:849
"The Stripe key is sk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdef in production config",
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
crates/wenlan-core/src/quality_gate.rs:1198
("The stripe key is sk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdef stored in the environment config file", "credential"),
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/wenlan-core/src/drift_guard.rs:7541
"Run embedding-only eval (main only, Linux)",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/wenlan-core/src/drift_guard.rs:7753
- name: Run embedding-only eval (main only, Linux)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/wenlan-core/src/eval/retrieval.rs:3237
"\n=== Pipeline Token Eval (Real LLM: {}) ===",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/wenlan-core/src/eval/retrieval_drift.rs:375
order. If intentional + the labeled eval (eval::retrieval) is still green, re-bless \
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/wenlan-core/src/quality_gate.rs:1740
println!("\nNOVELTY GATE EVAL (threshold: {:.2})", threshold);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/wenlan-server/src/web_fetch_tests.rs:26
"169.254.169.254",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMInventory / provenance · inv.binary · CWE-1104
app/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
app/.fastembed_cache
app/.fastembed_cache
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
crates/wenlan-core/eval/data/locomo_plus.json
crates/wenlan-core/eval/data/locomo_plus.json
Why it matters. link not followed
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/live-smoke-page-citations.sh:106
"The wenlan-citation-beacon service listens on port 4471 and exposes a /status endpoint for health checks."
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/live-smoke-page-citations.sh:107
"The wenlan-citation-beacon service authenticates callers with a rotating HMAC token refreshed every 15 minutes."
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/live-smoke-page-citations.sh:108
"The wenlan-citation-beacon service logs every request to a local SQLite audit table named beacon_requests."
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/live-smoke-page-citations.sh:125
-d "$(jq -n --argjson m "$MEMS_JSON" '{title:"Wenlan Citation Beacon Service", content:"Placeholder body about the beacon service.", source_memory_ids:$m}')" \
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/live-smoke-page-citations.sh:161
LEGACY_CONTENT="The wenlan-citation-beacon service logs every request to a local SQLite audit table named beacon_requests."
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/run-wenlan/SKILL.md:47
# ready:  curl -sf --max-time 2 http://127.0.0.1:17878/api/health  (poll up to ~120s)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/run-wenlan/SKILL.md:48
# check:  curl -sf http://127.0.0.1:17878/api/knowledge/path   → must be $DATA_DIR/pages
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/wenlan-core/src/quality_gate.rs:1377
"║    Noise latency:    {:.0}μs avg ({:.2}ms total)            ║",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/wenlan-core/src/quality_gate.rs:1382
"║    Legit latency:    {:.0}μs avg ({:.2}ms total)            ║",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/analyze_paired.py:701
"| feature | bench | n | n_touched | meanΔndcg(all) | 95% CI | Wilcoxon p | BH-sig | worst-cat Δ | ΔP99 lat(ms) | skip% | rec | G3 |"
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/analyze_paired.py:748
lines.append("| feature | bench | category | meanΔndcg | cat floor | verdict |")

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a5e731757643full audit observations/trust-audit/mcp-server/7xuanlu__wenlan.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a5e731757643BLOCKF35first audit
06

Questions

What is the Wenlan MCP server?

A living personal wiki. Wenlan turns your documents, notes, and AI chats into pages with links to their sources, and updates them as sources change without overwriting your edits. Claude Code, Codex and other AI tools can build on it.

What tools does Wenlan expose?

17 in total: 17 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Wenlan safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (35/100) and found 11 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Wenlan need?

It reads CARGO_REGISTRY_TOKEN, GH_TOKEN, GITHUB_TOKEN and WENLAN_REQUIRE_AUTHENTICODE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Wenlan run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as wenlan-readme-visuals at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (a5e731757643), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement