mdcp-doc-only

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the mdcp CLI tool for link validation (mdcp check) and executes repository-defined documentation validation commands. These actions are standard for the intended workflow of managing documentation shards and do not involve arbitrary command execution outside the scope of documentation processing.- [INDIRECT_PROMPT_INJECTION]: The skill processes external information such as work items, ticket descriptions, and existing repository shards to author new documentation. This ingestion of external data is a known surface for indirect prompt injection; however, the skill mitigates this by instructing the agent to adhere strictly to acceptance criteria and maintain a docs-only scope boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 09:48 PM
Security Audit — agent-trust-hub — mdcp-doc-only