wikipedia-research

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a Wikipedia research skill, and it does not request disproportionate credentials. However, its core behavior relies on executing an arbitrary local script from WIKIPEDIA_MCP_SCRIPT with no pinned provenance, package source, or release verification. That makes the install/execution trust materially weaker than the benign documentation suggests. Data flow appears limited to Wikipedia content retrieval, so this is not confirmed malware, but it is a medium-high security risk due to unverifiable execution dependency.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:15 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fwikipedia-research%2F@df953034afe71e5e86771a0a49e93cb34043ce3c