Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Pub Mdconv
v1.0.0Convert documents and files to Markdown using markitdown (PDF, Word, PowerPoint, Excel). And also 50+ models for image generation, video generation, text-to-...
⭐ 0· 178·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name implies a Markdown converter, but SKILL.md documents access to 50+ models (image, video, TTS, STT, search, email, SMS, scraping, etc.). The description also mentions these models, so functionality is intentional, but the name may mislead users who expect only local document-to-Markdown conversion.
Instruction Scope
Instructions use curl to call https://api.heybossai.com and show patterns for uploading/processing data and saving downloads. Converting documents will involve sending whole files to a third party; SKILL.md is truncated in the provided bundle so file‑upload details are missing. This broad network transmission of user files is outside what a user might assume from a simple 'markdown converter' and raises privacy/exfiltration concerns.
Install Mechanism
No install spec (instruction-only), so nothing is written to disk by default. Lowest install risk.
Credentials
Only one credential is required (SKILLBOSS_API_KEY) and it matches the API host used in the instructions. No unrelated secrets or config paths are requested.
Persistence & Privilege
always:false (not force-installed). Agent invocation is allowed (default) but the skill does not request elevated persistence or modify other skills.
What to consider before installing
This skill is essentially a client for a third‑party service (api.heybossai.com). Before installing: (1) assume any file you convert will be uploaded to that external service — do not send sensitive or regulated data unless you trust the vendor and have appropriate agreements; (2) confirm the service reputation, terms, and data retention/processing policies for heybossai.com; (3) review the missing/truncated portion of SKILL.md to see exactly how files are uploaded and what metadata is sent; (4) restrict the skill's read access or disable autonomous invocation if you don't want the agent to autonomously send files; (5) rotate and scope the API key you provide (use a dedicated key with limited permissions) and monitor its usage. If you expected a local-only Markdown converter, this skill is not that — it's a networked multi-model proxy and carries higher data‑exposure risk.Like a lobster shell, security has layers — review code before you run it.
latestvk97cs9vqe9nbhp7yxx15qn9ee582se3x
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
EnvSKILLBOSS_API_KEY
Primary envSKILLBOSS_API_KEY
