Back to skill

Security audit

make-to-markdown

Security checks for vulnerabilities and agentic risk

Overview

This document-conversion skill is purpose-aligned, but normal use can install packages, modify local tool environments, and overwrite files without enough separate user control.

Review before installing in a sensitive environment. Use it only where automatic package installation from PyPI/uv is acceptable, avoid untrusted documents unless conversion is sandboxed, confirm batch scopes and output paths carefully, and prefer explicit output paths for post_clean.py so originals are not overwritten.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

The code automatically executes pip install at runtime without explicit user approval. This expands the skill from local document conversion into network/package-management behavior and creates a supply-chain risk: a compromised package, poisoned index, or unexpected dependency resolution could cause arbitrary code execution in the agent environment.

Content

Scanner excerpt · scripts/convert.py (reported line 74)May include surrounding context.

python
try:
        print(f"  [INFO] 将执行: pip install {pkg_name}(从 PyPI 下载,约数 MB,不会上传本机数据)")
        print(f"  [依赖] 安装 {pkg_name} ...", end='', flush=True)
        result = subprocess.run(
            [sys.executable, '-m', 'pip', 'install', pkg_name, '-q'],
            capture_output=True, text=True, timeout=120,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

This code automatically installs markitdown and multiple extras through uv tool install --force at runtime. That introduces unaudited network retrieval and package execution into a document-conversion skill, creating significant supply-chain and remote code execution risk if packages or registries are compromised.

Content

Scanner excerpt · scripts/convert.py (reported line 139)May include surrounding context.

python
# 去重并安装
    unique_pkgs = list(dict.fromkeys(extra_pkgs))
    try:
        subprocess.run(
            [uv_bin, 'tool', 'install', 'markitdown', '--force']
            + [f'--with={pkg}' for pkg in unique_pkgs],
            capture_output=True, text=True, timeout=180,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
79% confidence
Finding

This subprocess executes an external converter (markitdown or uvx markitdown) on attacker-supplied files and may invoke uvx, which can fetch and run packages dynamically. In this skill context, converting untrusted documents through external tooling increases exposure to parser bugs, malicious file-triggered exploitation, and package-fetch side effects.

Content

Scanner excerpt · scripts/convert.py (reported line 198)May include surrounding context.

python
cmd = [bin_path, input_path, '-o', output_path]

    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
        if result.returncode == 0 and os.path.exists(output_path):
            return True
        # 检查是否为依赖缺失错误

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
74% confidence
Finding

The code invokes LibreOffice headless conversion on untrusted documents. While arguments are passed safely as a list, office-suite parsers have a long history of file-format vulnerabilities, so automatically processing arbitrary .doc/.ppt files with a native converter can expose the host to document-triggered exploitation.

Content

Scanner excerpt · scripts/convert.py (reported line 461)May include surrounding context.

python
try:
                abs_input = os.path.abspath(input_path)
                abs_output = os.path.abspath(output_dir)
                result = subprocess.run(
                    [soffice, '--headless', '--convert-to', convert_to,
                     '--outdir', abs_output, abs_input],
                    capture_output=True, text=True, timeout=60,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

The generic run_cmd wrapper enables arbitrary subprocess execution and, on Windows, forces shell=True. If any caller ever passes attacker-controlled or insufficiently validated input into cmd, this creates a command-injection primitive with broad execution capability beyond simple platform detection.

Content

Scanner excerpt · scripts/platform_detect.py (reported line 308)May include surrounding context.

python
if info.is_windows:
        kwargs.setdefault("shell", True)
        kwargs.setdefault("encoding", "utf-8")
    return subprocess.run(cmd, **kwargs)


# ── 模块自测 ──

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly instructs use of shell commands, file reads/writes, environment detection, package installation, and document conversion workflows, yet it declares no explicit permissions. This creates a governance and consent gap: an agent may gain broad filesystem and shell capabilities without transparent permission scoping or policy review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill promises that no traceable artifacts will remain, but elsewhere it requires persistent outputs such as batch results and _conversion_errors.log that can reveal source filenames and processing history. This inconsistency can mislead users about privacy guarantees and cause unintended retention of sensitive metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill automatically installs Python packages from package registries during normal operation, which exceeds the expected scope of simple document conversion. This broadens the trust boundary to external registries and dependency resolvers, creating avoidable supply-chain risk and unexpected code execution in the host environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code uses uv/uvx to dynamically install and run markitdown and extras, introducing network-capable package retrieval into the execution path. In an agent skill, this is dangerous because a conversion request can trigger external code acquisition and execution beyond the declared business function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This helper exposes a reusable command-execution primitive in a module that should only detect platform capabilities. Because it sets shell=True on Windows and accepts arbitrary cmd values from callers, it materially increases the chance that higher-level code turns this into command injection or unsafe execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to execute a remote installation script via irm ... | iex, which downloads and immediately runs code from the network without any integrity verification, pinning, or warning. If the remote endpoint, transport path, or install script is compromised, users could execute arbitrary code on their machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README repeatedly advertises 'automatic installation' of dependencies during normal tool execution, but it does not clearly warn users that running the skill may modify the local Python/tooling environment. In an agent skill context, implicit package installation increases supply-chain and change-management risk because execution can fetch and install code from external sources without an explicit user acknowledgement step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states support for EXIF/OCR, audio transcription, ZIP, and YouTube inputs, but it does not clearly disclose privacy and network implications such as metadata extraction, remote retrieval, and possible processing of sensitive embedded content. In a document-conversion skill, these capabilities can unexpectedly expose confidential data or trigger outbound network activity if users assume all processing is strictly local.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger phrases are broad enough that ordinary conversation about documents or Markdown could activate the skill unintentionally. Because the skill performs file access, shell execution, package installation, and batch processing, accidental invocation could lead to unreviewed operations on user files or directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic package installation occurs without user or administrator opt-in. Even if the package names are hardcoded, silently mutating the runtime environment and reaching out to registries is a security-relevant behavior that users may not expect from a converter skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill auto-installs markitdown extras through uv without explicit consent. This increases risk because a routine conversion can implicitly download and install additional code, broadening the attack surface and violating least surprise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script overwrites the input file by default when no explicit output path is provided, renames any existing target to a .bak file, writes the cleaned content, and then deletes the backup automatically. This creates a real integrity and recoverability risk: if the cleaning logic is destructive, produces incorrect output, or if the write only partially succeeds before cleanup, the user may lose the original document without an explicit confirmation step or durable backup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.