Findings › deepwiki

A

deepwiki

https://mcp.deepwiki.com/mcp
published scanned 2026-09-08 0 penalty

deepwiki is grade A with no findings: 39 rules ran across 5 surfaces and 3 tools, and nothing matched. 10 requests made. 0 penalty points — the scale counts problems, so zero is the best possible result.

What we tested

server_instructions text the server sends at connect, before any tool is called 2 items checked · nothing matched
initialize.instructions
DeepWiki MCP provides AI-powered documentation for GitHub repositories. Available tools: - read_wiki_structure: Get a list of documentation topics for a repository - read_wiki_contents: View full documentation about a repository - ask_question: Ask any question about a repository and get an AI-powered answer - list_available_repos: List your available repositories (private mode only) - generate_wiki: Generate a codebase wiki for a repository — only use when explicitly requested by the user (private mode only) - devin_automation_manage: Manage Devin automations — list, get, create, update, delete, or fetch the trigger event schemas (private mode only) - devin_billing_tag_manage: Manage Devin billing tags (groupings of Devin sessions for usage tracking) — list, get, create, add a member, list members (private mode only) - devin_code_scan_manage: Manage Devin code scans, sometimes referred to as 'security scans' or 'Devin Security Swarm' — list scans, list findings, list profiles, get a profile, create a scan, remediate a finding (private mode only) - devin_knowledge_manage: Manage Devin knowledge notes and suggestions — list, search, get, create, update, delete notes, view folder structure, list/view/dismiss knowledge suggestions (private mode only) - devin_mcp_server_manage: Manage org MCP server installations — install (marketplace or custom), update, enable, disable, delete (private mode only) - devin_oncall_manage: Devin Oncall operations — get an Oncall report's current responder membership, page through a responder's open issues, and ingest a dashboard into Oncall knowledge (private mode only) - devin_playbook_manage: Manage Devin playbooks — list, get, create, update, delete (private mode only) - devin_review_manage: Trigger a Devin Review for a pull request, fetch the latest review status, or fetch a completed review's findings (private mode only) - devin_schedule_manage: Manage scheduled Devin sessions — list, get, create, update, delete (private mode only) - devin_session_create: Create one or more child Devin sessions (private mode only) - devin_session_interact: Manage a Devin session — get status, send messages, sleep/terminate/archive/unarchive, read messages & attachments, manage tags (private mode only) - devin_session_events: Inspect session events — list summaries, fetch full details, or search event contents (private mode only) - devin_session_search: Search and filter Devin sessions (private mode only) - list_integrations: List all native integrations and MCP servers with their status and settings URLs (private mode only) - find_setting: Find Devin webapp settings pages and deep-link URLs for them (private mode only)
serverInfo.name
DeepWiki
tool_name the names of the tools 3 items checked · nothing matched
  • ask_question
  • read_wiki_contents
  • read_wiki_structure
tool_description what each tool says it does 3 items checked · nothing matched
tools/ask_question.description
Ask any question about a GitHub repository and get an AI-powered, context-grounded response.
tools/read_wiki_contents.description
View documentation about a GitHub repository.
tools/read_wiki_structure.description
Get a list of documentation topics for a GitHub repository.
tool_input_schema the descriptions on each tool’s input fields 4 items checked · nothing matched
tools/ask_question.inputSchema.properties.repoName.description
GitHub repository or list of repositories (max 10) in owner/repo format.
tools/ask_question.inputSchema.properties.question.description
The question to ask about the repository.
tools/read_wiki_contents.inputSchema.properties.repoName.description
GitHub repository in owner/repo format (e.g. "facebook/react").
tools/read_wiki_structure.inputSchema.properties.repoName.description
GitHub repository in owner/repo format (e.g. "facebook/react").
Tools 3 probed of 3 Requests 10 Protocol 2025-11-25 Layers deterministic, structural, 1 model
ModelExaminedFindingsStatusTime
claude-opus-5
anthropic
694 of 694 0 complete 632.4s

Tested and not found: Concealment · Consent bypass · Persona / role override · Model-directed imperative · Result-as-instruction · Promotional · Upgrade / pricing URL · Structural signal

What we found

Nothing matched. That is a statement about what could be seen, listed above — not a guarantee this server is clean.

Raw data

Reproduce it yourself. No credentials, no network:

mcp-audit scan-file data/snapshots/deepwiki/2026-09-08T11-37-25Z/manifest.json
Manifest hashsha256:798d07d1e3acabd004a1a9741e88d6be533da524fed201f3c8b8e56b18c0379b
Ruleset hashsha256:d26757507f22c9f8c437d7428a5ed19a46c3783c46f9ceb158b58a053eab1397
Scanner0.1.0
Scanned at2026-09-08T11:48:02.179Z

Not covered: [claude-opus-5] Classifier split 6 target(s) longer than 6000 characters into overlapping windows, costing 666 extra call(s). All of the text was examined; a match in any window is reported against the target. [claude-opus-5] Classifier skipped 4 target(s) shorter than 40 characters, which is below the length any of its rules could match. The deterministic layers still read them.