
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@tibia.sh/tibiawiki-mcp
Advanced tools
Offline MCP server for TibiaWiki: attribute queries over creatures, items, NPCs, quests and spells
An offline MCP server for TibiaWiki. It answers the questions the wiki itself cannot:
The server makes no network calls. Every answer comes from a local SQLite snapshot that installs with it, so queries return in milliseconds and work offline.
TibiaWiki runs on Fandom without Cargo, Semantic MediaWiki or CirrusSearch, so there is
no way to query it by attribute — every structured value is trapped inside Infobox
wikitext, and the built-in search returns Dragon Necklace for fire resistant dragon.
The public REST API over the same wiki exposes exactly one query parameter. Building a
local index is the only way to ask a real question.
node:sqlite landed in 22.5 and is unflagged from 22.13).uv only if you build your own index.pnpm add -g @tibia.sh/tibiawiki-mcp
The index comes with it as
@tibia.sh/tibiawiki-data, an 18 MB
dependency. You don't build anything first.
Two ways, and they ship different things.
As an MCP server only — the npm package:
claude mcp add --transport stdio tibiawiki -- npx -y @tibia.sh/tibiawiki-mcp
As a plugin — the server plus a skill that teaches an agent how to query it
(name resolution, the 100-is-neutral modifier convention, the data quirks that
produce wrong answers). The plugin pieces never reach the npm tarball, because
package.json has files: ["dist", "data/spell-areas.json"].
git clone https://github.com/tibia-sh/tibiawiki-mcp
cd tibiawiki-mcp
claude --plugin-dir .
The plugin runs the published package through npx, at the exact version it was released
with. A fresh clone needs no pnpm install and no build. The first start downloads the
package, and later starts work offline.
In a checkout, the plugin runs the published package at the pinned version, not your local source.
The MCP server alone gives an agent the tools. The bundled skill gives it the judgement to use them well — and it costs one line of context until it fires:
tibia_search before tibia_getmodifier_fire: 0
is immune to fire, not weak to ithitpoints: null means unrecorded, not zero — 433 creatures have no recorded healthimbuement.slots is a category list, not a countinclude_inactive: true| Tool | Answers |
|---|---|
tibia_search | "Is there a page called roughly X?" |
tibia_get | "Tell me everything about X." — creature, item, NPC, quest or spell |
tibia_find_creatures | "Which creatures match these stats?" |
tibia_find_items | "Which items match these stats?" |
tibia_how_to_obtain | "Where do I get X?" — drops, vendors and quest rewards in one call |
Damage modifiers are percentages where 100 is neutral: above 100 the creature takes
extra damage from that element. weak_to and resistant_to encode that for you.
Deprecated, event-only and unavailable pages are excluded by default; pass
include_inactive: true to see them.
A fresh install resolves the newest data release this server can read. An existing install keeps its release until you update it. For data fresher than the last release, build your own index:
tibiawiki-mcp build-index # about 6 minutes
It writes to $TIBIAWIKI_MCP_DB if you set it, and to
${XDG_CACHE_HOME:-~/.cache}/tibiawiki-mcp/tibiawiki.db otherwise. A failed build
never replaces a working index, because the new one is validated before it is
installed. Every answer reports indexGeneratedAt, so staleness is always visible to
whoever is asking.
The server reads the first index it finds:
$TIBIAWIKI_MCP_DB => an explicit path always wins${XDG_CACHE_HOME:-~/.cache}/tibiawiki-mcp/tibiawiki.db => an index you built@tibia.sh/tibiawiki-data => the data release installed with the serverA built index keeps winning over every later data release. If the server cannot read it, you get an error, not a fallback. Delete it to go back to the packaged one.
tibiawiki-mcp index-digest <path> prints a SHA-256 over the rows and columns the tools
read from an index. Two indexes with the same digest hold the same rows, in any stored
order. Build stamps such as indexGeneratedAt are left out. The data repo's drift job
will use it to tell new wiki content from a rebuild of the same content.
Spell area shapes are decoded once and committed to data/spell-areas.json. To find
out whether TibiaWiki has re-uploaded any of the source animations since:
pnpm decode-spell-areas <path-to-index.db> --check
It fetches metadata only, prints any image whose revision moved (and any new
candidate the file has never seen), and exits non-zero if there is drift — so it can
run on a schedule. Re-run without --check to regenerate.
Releases go to npm as @tibia.sh/tibiawiki-mcp, starting at 0.1.0.
The version number describes the server, not the data. The index ships separately as
@tibia.sh/tibiawiki-data, and its major
version is the index schema version. The server depends on ^3, the schema it reads.
test/data-package.test.ts keeps that range in step with MCP_SCHEMA_VERSION, so npm
refuses to install an index the server cannot read.
The caret is a deliberate exception to this repository's exact pins. An exact 3.0.0
would keep major 4 out just as well, so the caret is not what guards the schema. It lets
an install, a hosted instance included, pick up each compatible data release without a
server release. pnpm add does not write ^3, so edit the range by hand.
The tarball ships exactly dist/ and data/spell-areas.json, plus the package.json,
README.md and LICENSE npm always adds; test/packaging.test.ts runs
npm pack --dry-run as part of pnpm test, so anything else leaking in fails CI.
pnpm smoke <tarball-or-package@version> is the consumer-side check: it installs the
package into a throwaway directory and drives the installed binary over real stdio —
against a local tarball before publishing, against the registry after.
Data from TibiaWiki (https://tibia.fandom.com), licensed CC BY-SA. Tibia is made by CipSoft; game content and images are copyright CipSoft GmbH.
The index is generated by tibiawiki-sql (Apache-2.0). Images are deliberately never fetched or stored.
This project's own code is MIT licensed; see LICENSE. That covers the code only — the
data it serves is CC BY-SA and not ours to relicense.
FAQs
Offline MCP server for TibiaWiki: attribute queries over creatures, items, NPCs, quests and spells
The npm package @tibia.sh/tibiawiki-mcp receives a total of 4,478 weekly downloads. As such, @tibia.sh/tibiawiki-mcp popularity was classified as popular.
We found that @tibia.sh/tibiawiki-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.