Wikipedia Publisher

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Wikipedia/Wikidata drafting and publishing helper with expected network and credential use that users should handle carefully.

Install this only if you want an agent to help prepare and optionally publish wiki content. Use --dry-run before live edits, verify the API endpoint and page title, prefer sandbox or Draft pages, and use dedicated wiki/bot credentials rather than a primary account. Run citation fetching only on public URLs you are comfortable contacting from your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs the agent to use local scripts and external resources (`scripts/*.py`, reference files, URL enrichment, MediaWiki/Wikidata publishing), which implies file-read and network-capable behavior despite no declared permissions. This mismatch is dangerous because it can enable undeclared data access or outbound requests that users and policy controls are not expecting, especially in a publishing workflow that fetches URLs and can push content to external services.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal