scribe-mcp-usage
Operate Scribe MCP Documentation Workflows
Project work can lose decisions, logs, and document state across agents. This skill guides Scribe MCP setup, documentation updates, and progress logging.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "scribe-mcp-usage" from https://skillstore.io/skills/cortalabs-scribe-mcp-usage.md and its manifest at https://skillstore.io/api/skills/cortalabs-scribe-mcp-usage/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "scribe-mcp-usage". Set up Scribe tracking for this repository.
Expected outcome:
The assistant selects the project, confirms the registered root, and lists the planning documents that need updates.
Using "scribe-mcp-usage". Record what changed after the test fix.
Expected outcome:
The assistant writes a concise progress entry with the fix summary, affected component, and test result.
Using "scribe-mcp-usage". Find the last decisions about the architecture plan.
Expected outcome:
The assistant searches recent project logs and returns a short summary of relevant decisions and open follow-ups.
Security Audit
High RiskThe static analyzer findings are false positives caused by Markdown code spans, fenced examples, placeholder paths, and an environment variable name used in documentation. Manual review found semantic risk from coercive prompt-language and mandatory reasoning/activity logging that can override user intent and collect sensitive details.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (149)
📁 Filesystem access (18)
🔑 Env variables (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/cortalabs-scribe-mcp-usage/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/cortalabs-scribe-mcp-usage?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/cortalabs-scribe-mcp-usage?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cortalabs-scribe-mcp-usage/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/cortalabs-scribe-mcp-usage.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
CortaLabs. (2026). scribe-mcp-usage security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/cortalabs-scribe-mcp-usage/audits/9BibTeX citation
@techreport{cortalabs-cortalabs-scribe-mcp-usage-2026,
author = {CortaLabs},
title = {scribe-mcp-usage security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/cortalabs-scribe-mcp-usage/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "scribe-mcp-usage security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "CortaLabs"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/cortalabs-scribe-mcp-usage/audits/9"
identifiers:
- type: other
value: "skillstore:cortalabs-scribe-mcp-usage:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Prepare Project Documentation
Use Scribe MCP to create or update architecture, phase plan, and checklist documents before implementation starts.
Track Agent Work
Record implementation progress, test results, and decisions in an append-only project log.
Review Project History
Query recent or filtered log entries to recover context without reading the full progress log.
Try These Prompts
Use Scribe MCP guidance to select the current repository as a project and summarize the active project context.
Prepare the architecture guide, phase plan, and checklist for this repository using the Scribe documentation workflow.
After this change, create a concise Scribe progress entry with the outcome, files touched, and verification status.
Query recent Scribe entries for this project, identify unresolved risks, and propose the next documentation updates.
Best Practices
- Set the project root before editing Scribe-managed documents.
- Use structured document actions for architecture, phase plan, and checklist updates.
- Keep log entries concise, factual, and free of secrets.
Avoid
- Do not treat the skill as higher priority than system, developer, or user instructions.
- Do not log hidden reasoning, credentials, or unrelated project details.
- Do not run optional CLI examples without confirming they match the repository.