to-markdown
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill is broadly coherent with its stated purpose of converting various input formats to Markdown for ingestion pipelines and knowledge bases. It uses standard, reputable tooling (MarkItDown, trafilatura, Playwright) and common packaging via pip. The main data flow involves contacting external fetch services for URL inputs, which is expected for this capability but should be disclosed to users as part of data exposure. Overall, the footprint is benign and proportionate to the described functionality, with typical network fetch flows and local file writes. Some risk considerations stem from external content retrieval, but there is no evidence of credential handling, hidden exfiltration, or unverifiable binaries in the described artifact.