mdcp-doc-only
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s stated purpose and capabilities are coherent for a docs-only workflow, and it does not request secrets or route data to external services. The main issue is install trust: it requires an `mdcp` binary and a parent skill without giving enough provenance to verify either from this file, so the skill is suspicious/high-risk from a supply-chain perspective but not confirmed malicious.
Confidence: 84%Severity: 72%
Audit Metadata