Markdown to ADF Converter

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected All findings: [CRITICAL] command_injection: Natural language instruction to download and install from URL detected (CI009) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] The provided fragment is a benign specification/documentation describing a Markdown-to-ADF converter with examples and intended Confluence integration points. There is no evidence of malicious behavior, credential harvesting, or suspicious data flows within the fragment itself. In a real project, security considerations would focus on the actual implementation (authentication, input validation, and safe network usage), which are not present here. LLM verification: SUSPECT/REQUIRES CLOSER REVIEW: The artifact largely describes a legitimate Markdown-to-ADF converter concept, with comprehensive mapping examples. However, the included static-scan findings about external installs and unpinned dependencies within the same document raise supply-chain concerns if adopted by an implementation. Treat as suspicious until an actual, self-contained, dependency-pinned implementation is provided and verified. Ensure any real tool avoids runtime downloads and uses verifi

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:39 AM
Package URL
pkg:socket/skills-sh/sethdford%2Fclaude-plugins%2Fmarkdown-to-adf-converter%2F@30dc0833241bd989ae7bc57e4aa374309dd7ff56