MediaWikiCAUTION
Model Context Protocol (MCP) Server to connect your AI with any MediaWiki
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@professional-wiki/mediawiki-mcp-server) [](./LICENSE)
An MCP (Model Context Protocol) server that enables Large Language Model (LLM) clients to interact with any MediaWiki wiki.
Features
Tools
Every tool that operates on a wiki accepts an optional wiki argument naming the wiki to act on (the wiki-management and OAuth tools do not) — pass a wiki key (e.g. en.wikipedia.org) or the full mcp://wikis/{wikiKey} URI. Omit it to use the configured default wiki (see Configuration). Each tool response reports the wiki the call ran against. Each successful response carries its payload as prose in content and as JSON in structuredContent; see response channels.
Page reads
92a89b98bbcbOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mediawiki-mcp-server -- npx -y @professional-wiki/[email protected]
Exposed tools (40)
31 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
A | read | |
Company | read | A company. |
bar | read | d |
bucket-query | read | Runs a Bucket extension query against the targeted wiki. One row per match. Enabled only when the wiki has Bucket installed.\n\nGround bucket and field names first: schemas are JSON pages in the |
cargo-describe-table | read | Returns the field schema for a Cargo table on the targeted wiki: each field |
cargo-list-tables | read | Returns the names of all Cargo tables defined on the targeted wiki, including Cargo |
create-page | write | Creates a new wiki page with the provided content and returns the new page |
dummy | read | d |
foo | read | d |
get-category-members | read | Lists members of a category, returning each member |
get-file | read | Returns metadata for a file (uploader, timestamp, size, MIME type) along with download URLs for the thumbnail, preview, and original. The File: prefix is added automatically if omitted. |
get-links-here | read | Lists pages that reference a target wiki page, returning each referencing page |
get-page | read | Returns a single wiki page (wikitext source, rendered HTML, or metadata only). If the title does not exist, an error is returned. Use metadata=true to retrieve the revision ID (for edit-conflict detection), page size, and section outline. Set content= |
list-wikis | read | Lists every configured wiki: its key (pass as the |
mgmt-probe | read | non wiki tool |
neowiki-create-subject | write | Creates a new NeoWiki Subject on a wiki page and attaches its statements. Enabled only when the wiki has NeoWiki installed. Set isMain to make it the page\ |
neowiki-cypher-query | read | Runs a read-only Cypher query against the wiki\ |
neowiki-delete-subject | destructive | Deletes one NeoWiki Subject by ID from its page. Enabled only when the wiki has NeoWiki installed. Requires the edit right. Pre-1.0: the NeoWiki API may change without notice. |
neowiki-get-page-subjects | read | Lists the NeoWiki Subjects attached to a wiki page — each with full structured data — and identifies the page |
neowiki-get-schema | read | Returns one NeoWiki Schema |
neowiki-get-subject | read | Fetches one NeoWiki Subject by ID — its label, schema, and statements with typed values. Enabled only when the wiki has NeoWiki installed. Richer than a flattened Cypher node: it preserves multi-part values and per-statement types. |
neowiki-list-schemas | read | Lists the Schemas (entity types, e.g. Person, Company) defined in the wiki |
neowiki-search-subjects | read | Finds NeoWiki Subjects by label within a Schema, returning each match |
neowiki-update-subject | write | Replaces a NeoWiki Subject\ |
ping | read | |
probe | read | d |
qux | read | d |
slow-probe | read | test probe that yields before reading the wiki |
smw-list-properties | read | Lists Semantic MediaWiki properties on the targeted wiki. Enabled only when the wiki has SMW installed. Each entry has the property name, a copy-paste |
smw-query | read | Runs a Semantic MediaWiki |
undelete-page | read | Restores a previously deleted wiki page, including its full revision history, and returns the restored title. The page must currently be in a deleted state (from delete-page); fails if no deleted revisions exist for the title or the authenticated user lacks the undelete permission. |
update-file | write | Uploads a new revision of an existing file from the local disk, preserving prior revisions in the file history, and returns the file title and URL. The upload appears in the wiki |
update-file-from-url | write | Fetches a file from a remote web URL and uploads it as a new revision of an existing file, preserving prior revisions in the file history, and returns the file title and URL. The upload appears in the wiki |
upload-file | write | Uploads a file from the local disk into the wiki |
upload-file-from-url | write | Fetches a file from a remote web URL and uploads it into the wiki |
wiki-capture | read | d |
wikibase-add-statement | write | Adds one statement to a Wikibase item, property or lexeme and returns the new statement ID. Enabled only when the wiki is a Wikibase repository. Requires the edit right.\n\nThe value is given as text and interpreted by the property |
wikibase-get-entity | read | Returns one Wikibase item, property or lexeme as compact text: its label, description and aliases, then its statements, one line per property in the form \ |
wikibase-query | read | Runs a SPARQL query against the targeted wiki |
wikibase-search-entities | read | Finds Wikibase items and properties by label or alias on the targeted wiki, returning one |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
CALLBACK_URL="${PUBLIC_URL%/}/oauth/callback"--callbackUrl "$CALLBACK_URL" --approve --jsonOnSuccess)
log " callback: ${CALLBACK_URL}"log " 2. Callback URL (exact): ${CALLBACK_URL}"const SERVER_URL = `http://127.0.0.1:${PORT}/mcp`;const redirectUri = `http://127.0.0.1:${port}/oauth/callback`;const url = new URL(req.url ?? '/', `http://127.0.0.1`);
wikis: { w: { ...baseWiki, token: 'plain-secret-SENTINEL' } },neowiki-delete-subject
.mcpbignore
.oxfmtrc.json
.oxlintrc.json
vi.stubEnv('CONFIG', '/etc/mediawiki-mcp/absent.json');expect(output).toContain('/etc/mediawiki-mcp/absent.json');new UploadValidationError('"/etc/passwd" is not allowed'),filepath: '/etc/passwd',
'"/etc/passwd" is not allowed by the configured upload directories.',
import { monotonicNow } from '../../runtime/clock.ts';import { monotonicNow } from '../../runtime/clock.ts';import { isErrnoException } from '../../errors/isErrnoException.ts';import { recordStoreFlush, recordStoreFlushFailure } from '../../runtime/metrics.ts';import { monotonicNow } from '../../runtime/clock.ts';'Refusing to fetch URL resolving to non-public address 169.254.169.254 (linkLocal): http://169.254.169.254/',
const result = await dispatch(addWiki, ctx)({ wikiUrl: 'http://169.254.169.254/' });headers: { Location: 'https://169.254.169.254/latest/meta-data/' },Gates applied: no_behavioural_pass.
92a89b98bbcbfull audit observations/trust-audit/mcp-server/professionalwiki__mediawiki-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 92a89b98bbcb | CAUTION | C | 79 | first audit |
Questions
What is the MediaWiki MCP server?
Model Context Protocol (MCP) Server to connect your AI with any MediaWiki
What tools does MediaWiki expose?
40 in total: 31 read-only, 8 that write, and 1 that can delete or overwrite (neowiki-delete-subject). Every one is listed on this page with its risk.
Is MediaWiki safe to connect to an agent?
With care. The audit graded it C (79/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does MediaWiki need?
It reads MCP_OAUTH2_CLIENT_ID, MCP_OAUTH2_CLIENT_SECRET, MCP_OAUTH_CREDENTIALS_FILE, MCP_OAUTH_NO_BROWSER and MCP_OAUTH_PROXY_STORE_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MediaWiki run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @professional-wiki/mediawiki-mcp-server at 0.19.0.
How current is this page?
The grade is for one exact copy of the source (92a89b98bbcb), read on 2026-10-07. The repository is watched and re-audited when it changes.