Atlas / MCP servers / professionalwiki / MediaWiki

MediaWikiCAUTION

mcp/professionalwiki/mediawiki-2

Model Context Protocol (MCP) Server to connect your AI with any MediaWiki

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
40 31r · 8w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
136
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@professional-wiki/mediawiki-mcp-server) [](./LICENSE)

An MCP (Model Context Protocol) server that enables Large Language Model (LLM) clients to interact with any MediaWiki wiki.

Features

Tools

Every tool that operates on a wiki accepts an optional wiki argument naming the wiki to act on (the wiki-management and OAuth tools do not) — pass a wiki key (e.g. en.wikipedia.org) or the full mcp://wikis/{wikiKey} URI. Omit it to use the configured default wiki (see Configuration). Each tool response reports the wiki the call ran against. Each successful response carries its payload as prose in content and as JSON in structuredContent; see response channels.

Page reads

Read from source at commit 92a89b98bbcbOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mediawiki-mcp-server -- npx -y @professional-wiki/[email protected]
03

Exposed tools (40)

31 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
Aread
CompanyreadA company.
barreadd
bucket-queryreadRuns a Bucket extension query against the targeted wiki. One row per match. Enabled only when the wiki has Bucket installed.\n\nGround bucket and field names first: schemas are JSON pages in the
cargo-describe-tablereadReturns the field schema for a Cargo table on the targeted wiki: each field
cargo-list-tablesreadReturns the names of all Cargo tables defined on the targeted wiki, including Cargo
create-pagewriteCreates a new wiki page with the provided content and returns the new page
dummyreadd
fooreadd
get-category-membersreadLists members of a category, returning each member
get-filereadReturns metadata for a file (uploader, timestamp, size, MIME type) along with download URLs for the thumbnail, preview, and original. The File: prefix is added automatically if omitted.
get-links-herereadLists pages that reference a target wiki page, returning each referencing page
get-pagereadReturns a single wiki page (wikitext source, rendered HTML, or metadata only). If the title does not exist, an error is returned. Use metadata=true to retrieve the revision ID (for edit-conflict detection), page size, and section outline. Set content=
list-wikisreadLists every configured wiki: its key (pass as the
mgmt-probereadnon wiki tool
neowiki-create-subjectwriteCreates a new NeoWiki Subject on a wiki page and attaches its statements. Enabled only when the wiki has NeoWiki installed. Set isMain to make it the page\
neowiki-cypher-queryreadRuns a read-only Cypher query against the wiki\
neowiki-delete-subjectdestructiveDeletes one NeoWiki Subject by ID from its page. Enabled only when the wiki has NeoWiki installed. Requires the edit right. Pre-1.0: the NeoWiki API may change without notice.
neowiki-get-page-subjectsreadLists the NeoWiki Subjects attached to a wiki page — each with full structured data — and identifies the page
neowiki-get-schemareadReturns one NeoWiki Schema
neowiki-get-subjectreadFetches one NeoWiki Subject by ID — its label, schema, and statements with typed values. Enabled only when the wiki has NeoWiki installed. Richer than a flattened Cypher node: it preserves multi-part values and per-statement types.
neowiki-list-schemasreadLists the Schemas (entity types, e.g. Person, Company) defined in the wiki
neowiki-search-subjectsreadFinds NeoWiki Subjects by label within a Schema, returning each match
neowiki-update-subjectwriteReplaces a NeoWiki Subject\
pingread
probereadd
quxreadd
slow-probereadtest probe that yields before reading the wiki
smw-list-propertiesreadLists Semantic MediaWiki properties on the targeted wiki. Enabled only when the wiki has SMW installed. Each entry has the property name, a copy-paste
smw-queryreadRuns a Semantic MediaWiki
undelete-pagereadRestores a previously deleted wiki page, including its full revision history, and returns the restored title. The page must currently be in a deleted state (from delete-page); fails if no deleted revisions exist for the title or the authenticated user lacks the undelete permission.
update-filewriteUploads a new revision of an existing file from the local disk, preserving prior revisions in the file history, and returns the file title and URL. The upload appears in the wiki
update-file-from-urlwriteFetches a file from a remote web URL and uploads it as a new revision of an existing file, preserving prior revisions in the file history, and returns the file title and URL. The upload appears in the wiki
upload-filewriteUploads a file from the local disk into the wiki
upload-file-from-urlwriteFetches a file from a remote web URL and uploads it into the wiki
wiki-capturereadd
wikibase-add-statementwriteAdds one statement to a Wikibase item, property or lexeme and returns the new statement ID. Enabled only when the wiki is a Wikibase repository. Requires the edit right.\n\nThe value is given as text and interpreted by the property
wikibase-get-entityreadReturns one Wikibase item, property or lexeme as compact text: its label, description and aliases, then its statements, one line per property in the form \
wikibase-queryreadRuns a SPARQL query against the targeted wiki
wikibase-search-entitiesreadFinds Wikibase items and properties by label or alias on the targeted wiki, returning one
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (12 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/provision-dev-wiki.sh:76
CALLBACK_URL="${PUBLIC_URL%/}/oauth/callback"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/provision-dev-wiki.sh:87
--callbackUrl "$CALLBACK_URL" --approve --jsonOnSuccess)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/provision-dev-wiki.sh:178
log "  callback: ${CALLBACK_URL}"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/provision-dev-wiki.sh:192
log "  2. Callback URL (exact): ${CALLBACK_URL}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/mcp-checks.cjs:20
const SERVER_URL = `http://127.0.0.1:${PORT}/mcp`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/browserAuth.ts:84
const redirectUri = `http://127.0.0.1:${port}/oauth/callback`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/browserAuth.ts:232
const url = new URL(req.url ?? '/', `http://127.0.0.1`);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/config/loadConfig.test.ts:310
wikis: { w: { ...baseWiki, token: 'plain-secret-SENTINEL' } },
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
neowiki-delete-subject
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxfmtrc.json
.oxfmtrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/config/loadConfig.test.ts:44
vi.stubEnv('CONFIG', '/etc/mediawiki-mcp/absent.json');
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/config/loadConfig.test.ts:50
expect(output).toContain('/etc/mediawiki-mcp/absent.json');
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/tools/update-file.test.ts:58
new UploadValidationError('"/etc/passwd" is not allowed'),
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/tools/update-file.test.ts:64
filepath: '/etc/passwd',
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/tools/upload-file.test.ts:32
'"/etc/passwd" is not allowed by the configured upload directories.',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/authorizationServer/cimd.ts:3
import { monotonicNow } from '../../runtime/clock.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/authorizationServer/proxyStore.ts:2
import { monotonicNow } from '../../runtime/clock.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/authorizationServer/proxyStorePersistence.ts:3
import { isErrnoException } from '../../errors/isErrnoException.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/authorizationServer/proxyStorePersistence.ts:4
import { recordStoreFlush, recordStoreFlushFailure } from '../../runtime/metrics.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/authorizationServer/proxyStorePersistence.ts:8
import { monotonicNow } from '../../runtime/clock.ts';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/tools/add-wiki.test.ts:161
'Refusing to fetch URL resolving to non-public address 169.254.169.254 (linkLocal): http://169.254.169.254/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/tools/add-wiki.test.ts:167
const result = await dispatch(addWiki, ctx)({ wikiUrl: 'http://169.254.169.254/' });
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/transport/httpFetch.test.ts:158
headers: { Location: 'https://169.254.169.254/latest/meta-data/' },
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 92a89b98bbcbfull audit observations/trust-audit/mcp-server/professionalwiki__mediawiki-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0792a89b98bbcbCAUTIONC79first audit
06

Questions

What is the MediaWiki MCP server?

Model Context Protocol (MCP) Server to connect your AI with any MediaWiki

What tools does MediaWiki expose?

40 in total: 31 read-only, 8 that write, and 1 that can delete or overwrite (neowiki-delete-subject). Every one is listed on this page with its risk.

Is MediaWiki safe to connect to an agent?

With care. The audit graded it C (79/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MediaWiki need?

It reads MCP_OAUTH2_CLIENT_ID, MCP_OAUTH2_CLIENT_SECRET, MCP_OAUTH_CREDENTIALS_FILE, MCP_OAUTH_NO_BROWSER and MCP_OAUTH_PROXY_STORE_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MediaWiki run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @professional-wiki/mediawiki-mcp-server at 0.19.0.

How current is this page?

The grade is for one exact copy of the source (92a89b98bbcb), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement