Back to skill

Security audit

MarkItDown文档转换中文版

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed document-to-Markdown converter, with ordinary setup risks from installing dependencies and optional system packages.

Install this only if you are comfortable with MarkItDown and its optional dependencies. Prefer a virtual environment or pipx under your user account, pin versions where possible, and review any sudo apt-get commands before running them. Batch conversion will recursively read the directory you provide, so point it only at documents you intend to convert.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:100
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:100-106
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install "markitdown[all]"
pipx install 'markitdown[all]'

Technical Analysis

The installation instructions retrieve the latest available version of markitdown and all optional dependencies without a version constraint, lockfile, or cryptographic integrity hashes. Installing the all extra also expands the supply-chain attack surface by resolving numerous optional transitive packages that may not be required for every use case.

Although the documented package is consistent with the Skill's stated purpose, installation is not reproducible and the exact dependency set cannot be verified against the audited project. An upstream compromise, malicious transitive release, dependency confusion event, or unexpected incompatible update could therefore introduce attacker-controlled code after this Skill has been reviewed.

Attack Path

  1. An attacker compromises the upstream package, one of its optional transitive dependencies, or the relevant package-distribution account.
  2. The attacker publishes a malicious release that satisfies the unrestricted dependency specification.
  3. A user follows the documented pip install "markitdown[all]" or pipx install 'markitdown[all]' instructions.
  4. The package manager resolves and installs the malicious release because no audited version or integrity hash is required.
  5. Malicious code may execute during source-package build or later when the installed package is imported and used by the scripts.

Impact Assessment

Successful exploitation could execute code with the privileges of the account performing the installation or running the conversion scripts. This may permit access to that user's readable documents, environment variables, credentials, output files, and other accessible local resources.

The impact is gener ...[truncated 274 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin markitdown to a specifically reviewed version rather than installing an unrestricted latest release.
  2. Generate and commit a dependency lockfile containing exact versions for all transitive dependencies.
  3. Require cryptographic package hashes, such as through a hashed requirements file and pip install --require-hashes.
  4. Install only the optional extras required by the intended conversion formats instead of using the broad all extra.
  5. Perform installation in an isolated virtual environment under an unprivileged account.
  6. Add automated dependency vulnerability and provenance scanning to the release process.
  7. Review and deliberately update dependency pins rather than allowing package resolution to change on each installation.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码的核心用途与“文档转 Markdown”这一主目标基本一致,但声明显著夸大了能力范围。实际实现只接受一个 input_file 和一个可选 output_file,调用 MarkItDown().convert() 后将 text_content 写入 Markdown 文件,因此只能确认其具备单文件转换能力。代码中没有遍历目录、批处理接口、图片导出、附件提取或专门的格式保留逻辑。根据评估标准,这属于描述与实际行为不一致的能力夸大,应判定为 mismatch。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description and main heading/content present the skill as Chinese-only, including example invocations in Chinese, but do not state that the skill is region- or language-specific or offer an alternative language. This can violate language/locale policy when users are not given an opt-in or choice.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
83% confidence
Finding

The documentation recommends sudo apt-get install pipx, encouraging privileged system modification during setup. Running package-management commands with elevated privileges increases the blast radius of mistakes, dependency confusion, or compromised repositories, especially in shared or production environments.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
pip install "markitdown[all]"

# 或安装pipx包管理应用,通过pipx安装markitdown
sudo apt-get install pipx
# 使用pipx安装markitdown包 all表示支持所有格式
pipx install 'markitdown[all]'
# 将通过pipx安装的包路径放入当前变量PATH内

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

The instruction to use sudo apt-get install poppler-utils normalizes privileged package installation as part of routine use. While common in Linux administration, embedding sudo-based setup in a skill can lead users or automated agents to perform unnecessary root actions, increasing risk from misconfiguration or malicious package/source substitution.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
某些格式转换可能需要额外的系统依赖:

- **PDF 处理**: `brew install poppler` (macOS) 或 `sudo apt-get install poppler-utils` (Linux)
- **OCR**: `brew install tesseract` (macOS) 或 `sudo apt-get install tesseract-ocr` (Linux)

## 验证安装

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

The documented sudo apt-get install tesseract-ocr command similarly promotes elevated system changes. In the context of an agent skill, recommendations for root-level installation are more sensitive because they may be copied into automation or executed without adequate review, potentially exposing the host to broader compromise if the package source or environment is untrusted.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
某些格式转换可能需要额外的系统依赖:

- **PDF 处理**: `brew install poppler` (macOS) 或 `sudo apt-get install poppler-utils` (Linux)
- **OCR**: `brew install tesseract` (macOS) 或 `sudo apt-get install tesseract-ocr` (Linux)

## 验证安装

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language strings entirely in Chinese in the module docstring and console output, with no indication that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains docstrings, help text, and console messages entirely in Chinese, which imposes a specific language on users without any opt-in or alternative locale. The policy explicitly flags language or locale constraints when the skill does not offer user choice or clearly justify the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing error/output messages are written only in Chinese, including usage and failure instructions. This imposes a specific language on users without opt-in or explanation, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.