mdcp-doc-only
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
mdcpCLI tool for link validation (mdcp check) and executes repository-defined documentation validation commands. These actions are standard for the intended workflow of managing documentation shards and do not involve arbitrary command execution outside the scope of documentation processing.- [INDIRECT_PROMPT_INJECTION]: The skill processes external information such as work items, ticket descriptions, and existing repository shards to author new documentation. This ingestion of external data is a known surface for indirect prompt injection; however, the skill mitigates this by instructing the agent to adhere strictly to acceptance criteria and maintain a docs-only scope boundary.
Audit Metadata