markitdown

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/api_reference.md

The provided fragment is a documentation/API reference and contains no direct malicious code. However, the documented features (third-party plugins via package entry_points, custom converters executing in-process, and optional outbound LLM/Azure integrations) create realistic supply-chain and data-exfiltration risks: a malicious or compromised plugin or converter can read sensitive documents, environment variables, and then exfiltrate them to remote services. Treat plugins and custom converters as untrusted code, use least-privilege credentials, run conversions in isolated environments for sensitive data, and vet and lock plugin dependencies before installation.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:56 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fmarkitdown%2F@c34901af08a5dac40ec9035b4706e5c09c91d1b7