markitdown

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md describes a legitimate file-to-Markdown conversion tool with optional integrations to external services (OpenRouter, Azure Document Intelligence, YouTube). I found no evidence of hidden backdoors, obfuscated payloads, download-and-execute instructions (curl|bash), or references to suspicious domains. The primary security considerations are: (1) optional features transmit user documents to external services when enabled — users should be aware and vet those endpoints and their data handling policies; (2) the plugin system and installation of third-party plugins introduces transitive trust/supply-chain risk — only install reviewed plugins; and (3) in automated agent contexts, granting shell (Bash) or broad tool permissions increases potential for misuse. Overall the content is consistent with its stated purpose and presents moderate supply-chain/privacy considerations but no clear malicious behavior.

Confidence: 90%Severity: 85%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/K-Dense-AI%2Fclaude-scientific-skills%2Fmarkitdown%2F@b395b0730fa395a4060453cd0e9db437ac245704