baoyu-markdown-to-html
Warn
Audited by Snyk on Feb 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill downloads arbitrary HTTP/HTTPS image URLs as part of convertMarkdown (resolveImagePath -> downloadFile in scripts/main.ts) and also constructs/fetches PlantUML SVGs from a remote PlantUML server (scripts/md/extensions/plantuml.ts), so it ingests untrusted third‑party web content into its workflow.
Audit Metadata