Back to skill

Security audit

Wikipedia MCP

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Wikipedia/Wikimedia research skill with broad but disclosed public-data lookup tools, plus privacy and dependency caveats.

Install only if you are comfortable with your Wikipedia searches, article titles, usernames/IPs you look up, and related metadata being sent to Wikimedia/Wikipedia services. Treat public editor profiling tools with care, and consider pinning dependencies or using a locked environment before deployment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description is directionally correct about being a Wikipedia research/lookup tool, and many listed features are genuinely present: search, summaries, random article/facts, dinosaur facts, featured article, on-this-day events, categories, outgoing links, pageviews, news, top reads, and 10-language support. However, the code substantially exceeds the declared scope. It includes numerous additional tools for media/Commons access, article structure extraction, revision and live-change tracking, source/reference analysis, contributor and quality assessment, graph/path exploration, geosearch, translations, and even a non-Wikipedia curated quote feature. Because the evaluation asks to flag undeclared capabilities and inconsistent resources, this is a mismatch: the actual behavior is materially broader than the declared description and accesses Wikimedia Commons/wikimedia.org resources not mentioned in the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents the skill as a general Wikipedia access tool focused on article search, summaries, facts, categories/links, pageviews, news, and most-read content. The supplied code chunk clearly exposes a broader and materially different set of capabilities centered on editorial auditing and provenance analysis of Wikipedia content and editors. These include inspecting exact past revisions, generating diffs between revisions, parsing disambiguation pages, profiling editor contributions, finding unsourced claims, reading talk-page disputes, extracting maintenance warnings, checking article protection, and measuring article activity. These are not merely implementation details supporting the declared lookup features; they are separate end-user tools with distinct purposes. Therefore the description understates the skill’s actual behavior and is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
78% confidence
Finding

Based on the supplied chunk, the implementation is an MCP/JSON-RPC server that routes tool calls to a set of article-oriented functions whose names do not match the declared feature list. The declared description emphasizes broad Wikipedia lookup functions like search, summaries, random facts, featured content, pageviews, news, and multilingual support, but those capabilities are not evidenced here. Instead, the visible tools suggest different functionality around article flags/protection/pulse, citation sources, navigation/pathing, and date-specific article lookup. While this may be only a partial file, the visible exposed tool surface materially differs from the declared description, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk is a comprehensive smoke test for a server with 47 tools, far exceeding the declared description. While the declared purpose accurately covers some major capabilities (search, summaries, dinosaur facts, featured article, historical events, categories, links, pageviews, news, top reads, multilingual support), it omits many substantial behaviors that are first-class features rather than minor implementation details. These include revision inspection, diffs, backlinks, nearby geosearch, translations, user and talk-page analysis, citation/maintenance/protection tooling, recent changes, infobox/quality/reference extraction, related/contributor analysis, article pathing, historical snapshots, and media search/listing. This is therefore a description-behavior mismatch due to significant undeclared capabilities, even though the code still operates within Wikipedia/Wikimedia-related resources and the primary domain is consistent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope or permissions despite clearly requiring network access to external Wikimedia/Wikipedia endpoints. In agent ecosystems, missing scope declarations can cause users or orchestrators to under-estimate what the skill can do, weakening review, consent, and policy enforcement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation exposes a much broader capability set than the manifest suggests, including editor profiling, revision diffs, talk-page mining, protection status, contributor analysis, and trust/audit tooling. This scope mismatch is dangerous because downstream users, policy engines, or approval workflows may grant the skill based on a narrow 'Wikipedia lookup' description while the code enables broader surveillance and profiling behaviors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file is a code file, so SQP-3 applies to natural-language strings and docstrings. The quote tool explicitly says non-English lang values are accepted but still return English quotes, which forces a specific language output without user opt-in and conflicts with locale-choice expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user_contribs functionality enables profiling of named editors or IPs across Wikipedia, including registration date, edit counts, edited pages, timestamps, and activity patterns. In the context of a skill described as general knowledge and article research, this is broader than expected and can be used for deanonymization, targeting, or behavioral surveillance of contributors.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · src/server.py (reported line 4040)May include surrounding context.

python
# article_protection — is this article locked, and for how long?
# ---------------------------------------------------------------------------
_AP_LEVEL_MEANINGS = {
    "autoconfirmed": "autoconfirmed accounts only (at least 4 days old with "
                     "10+ edits) — anonymous and brand-new accounts are blocked",
    "extendedconfirmed": "extended-confirmed accounts only (at least 30 days "
                         "old with 500+ edits)",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · src/server.py (reported line 4132)May include surrounding context.

python
# article_protection — is this article locked, and for how long?
# ---------------------------------------------------------------------------
_AP_LEVEL_MEANINGS = {
    "autoconfirmed": "autoconfirmed accounts only (at least 4 days old with "
                     "10+ edits) — anonymous and brand-new accounts are blocked",
    "extendedconfirmed": "extended-confirmed accounts only (at least 30 days "
                         "old with 500+ edits)",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language tool description reinforces that the lang parameter accepts other languages but will still return English content. That is a locale policy issue because it silently overrides the user's chosen language rather than offering a genuine choice or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code includes natural-language expectations that explicitly require German-language behavior via lang="de", such as verifying German links and content. Per the policy, forcing a specific locale without user opt-in can be a language/locale policy violation unless clearly justified; in this test file, no justification or user-choice mechanism is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

These assertions require German-language behavior for on_this_day when lang="de" is supplied, embedding a locale constraint in the file's natural-language expectations. The file does not state that this is a user-selected optional mode or otherwise justify the locale requirement, which can conflict with the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The test expectations explicitly validate German-language behavior for deaths_on_this_day using lang="de", but the natural-language context does not explain that this is an optional user-selected locale path. Without that clarification, the file contains a locale-specific requirement that can be read as policy-noncompliant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This section hard-codes German locale expectations for births_on_this_day through natural-language assertions. Because the file does not explicitly frame the locale as user-selected or justified, it risks violating the policy against forcing a specific language or locale without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README documents that the server calls external Wikipedia/Wikimedia APIs, but it does not clearly warn users that their queries, article titles, and related metadata will be transmitted to third-party services. In a research-oriented MCP skill, this is a genuine privacy/transparency issue because users may submit sensitive topics, internal project names, or investigative queries assuming the tool is local-only.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified as requests>=2.28.0 without an upper bound or exact pin, which makes builds non-reproducible and can cause different environments to resolve to different versions. In security terms, this increases supply-chain risk because a vulnerable or breaking release could be installed without review, and it also makes it hard to verify whether known advisories affect the deployed version.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin the version, there is no way to determine from this file whether installation will select a patched or vulnerable release. In a skill that retrieves external Wikipedia content over the network, an HTTP client library is directly exposed to untrusted remote input, so leaving the version unconstrained increases the chance of deploying an affected release.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.