mdcp-design-architecture
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s documented behavior is mostly coherent and local-only, but it requires an mdcp CLI whose provenance is not established here and it depends on a parent skill installation. The primary risk is supply-chain and transitive trust, not confirmed malicious behavior or credential exfiltration.
Confidence: 85%Severity: 78%
Audit Metadata