convert-to-markdown

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's purpose-capability alignment is coherent for a web-to-markdown extractor. However, the install mechanism (curling a raw GitHub script and piping to sh) introduces a high-risk supply-chain/vector concern that is disproportionate to the core task and unverifiable. This single risk factor, combined with the potential for clipboard/file outputs to expose sensitive content, warrants at least a suspicious risk posture, with the install vector elevating security risk significantly. Recommend replacing the install approach with a trusted, verifiable package source (official registry, signed releases, or container image) and clearly defining data handling/privacy for outputs.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:41 PM
Package URL
pkg:socket/skills-sh/gupsammy%2FClaudest%2Fconvert-to-markdown%2F@5a4846f3c50ff684b8dd3f5195680bac93a52506