Back to skill

Security audit

markdown-converter

Security checks for vulnerabilities and agentic risk

Overview

This converter is not malicious, but it needs review because it runs unpinned third-party conversion code and includes an under-explained remote document-processing path that can send document URLs or content to SkillBoss.

Install only if you are comfortable with these trust boundaries. Prefer a pinned, reviewed markitdown version for local conversion, avoid --use-plugins unless the plugins are vetted, and do not set or use SKILLBOSS_API_KEY unless you intentionally want SkillBoss to receive the submitted document URLs, metadata, or content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Package Retrieval and Execution Through uvx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–26
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
# Convert to stdout
uvx markitdown input.pdf

# Save to file
uvx markitdown input.pdf -o output.md
uvx markitdown input.docx > output.md

# From stdin
cat input.pdf | uvx markitdown

The Skill also documents an option that expands the executable dependency surface:

bash
--use-plugins  # Enable 3rd-party plugins

Technical Analysis

The documented commands use uvx markitdown without specifying an audited package version or verifying package integrity. uvx can retrieve the package and its transitive dependencies from a configured package index before executing them. Consequently, the code that runs may change after this Skill has been reviewed.

This creates a supply-chain risk if the package, one of its dependencies, the package index, or the package-resolution configuration is compromised. The optional --use-plugins flag further increases the risk because third-party plugin code may be loaded and executed without an allowlist or version constraints.

Attack Path

  1. An attacker compromises a future markitdown release, a transitive dependency, an enabled plugin, or the configured package source.
  2. The user or Agent follows the Skill instructions and invokes uvx markitdown without a pinned version.
  3. uvx resolves and downloads the attacker-controlled package or dependency.
  4. The downloaded code executes with the same operating-system identity and permissions as the Agent.
  5. The malicious package can access documents supplied for conversion and any other resources available to that process.

Impact Assessment

Successful exploitation could result in arbitrary code execution with the invoking Agent's privileges. Depending on the Agent's environment, the malicious dependency could read ...[truncated 305 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin markitdown to a specifically audited version in every command, rather than resolving the latest available release.
  • Use a lockfile or equivalent mechanism to pin and verify all transitive dependencies.
  • Configure uvx to use only an approved package index and apply available hash or signature verification.
  • Test dependency updates in a controlled environment before changing the pinned version.
  • Run conversion in a sandbox with minimal filesystem access, restricted environment variables, and network access disabled unless necessary.
  • Do not recommend --use-plugins by default. If plugin support is necessary, maintain an explicit allowlist and pin each plugin and its dependencies.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:52
Finding

Optional Third-Party Processing Can Disclose Sensitive Document Information

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 52–82
Vulnerability Type: Sensitive information transmission and excessive credential requirement
Risk Level: Low

The Skill metadata additionally declares the credential at line 4:

yaml
requires.env: [SKILLBOSS_API_KEY]

Vulnerable Code

python
import requests, os

SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillboss.co/v1"

def pilot(body: dict) -> dict:
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,
        timeout=60,
    )
    return r.json()

# Enhanced PDF/document extraction via SkillBoss API Hub
result = pilot({
    "type": "scraper",
    "inputs": {"url": "https://example.com/document.pdf"},
    "prefer": "balanced"
})
content = result["result"]["data"]["markdown"]

Technical Analysis

The enhanced-processing example intentionally sends a bearer credential and request data to https://api.skillboss.co/v1/pilot. The API key transmission is consistent with authentication to the declared service and is not evidence of covert credential exfiltration. However, the request also discloses document URLs and associated processing parameters to a third party. Other document-input forms supported by the service may disclose document content as well.

Remote processing is optional and is not required for the Skill's primary local conversion workflow. Nevertheless, SKILLBOSS_API_KEY is declared as a general required environment variable. This exceeds the minimum requirements of local conversion and unnecessarily increases credential exposure to the Skill execution environment. The instructions also do not require explicit user consent before remote processing or explain the third party's data-retention and privacy boundaries.

Attack Path

...[truncated 1234 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove SKILLBOSS_API_KEY from globally required environment variables and request it only when the user explicitly chooses remote processing.
  • Keep local conversion as the default and require informed confirmation before transmitting any URL, document, or metadata to SkillBoss.
  • Clearly document which request fields, files, URLs, and credentials leave the local environment.
  • Warn users not to submit private or pre-signed URLs unless they accept third-party disclosure.
  • Use narrowly scoped, short-lived API tokens and provide straightforward rotation and revocation procedures.
  • Ensure credentials and request bodies are redacted from application, proxy, and error logs.
  • Validate destination URLs, prohibit unexpected redirects where possible, and restrict outbound requests to the documented HTTPS API hostname.
  • Document the external service's retention, access-control, and privacy expectations before recommending it for sensitive documents.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description promises local conversion using markitdown but the body also directs users to a separate remote API-based extraction path. That mismatch can mislead users about trust boundaries and cause inadvertent disclosure of documents to external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description lists formats like YouTube URLs and later references SkillBoss API Hub, but it does not clearly warn that some conversions may involve external services and transmit content or metadata off-host. Users may therefore process confidential files under the false assumption that all conversion is local.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill repeatedly instructs users to run uvx markitdown without pinning a specific package version. Because uvx resolves and executes code from the package ecosystem at runtime, an upstream compromise, typo-squatted dependency, or breaking update could cause unreviewed code execution in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This example invokes uvx markitdown without a pinned version, causing runtime retrieval and execution of the latest available package code. In a skill intended for document handling, that creates a supply-chain execution path unrelated to the user's immediate document content and increases compromise risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The command shown on this line fetches and runs markitdown dynamically via uvx without version pinning. That exposes users to unexpected code changes and potential malicious upstream updates, turning a conversion skill into an implicit remote code execution trust decision.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Reading from stdin into an unpinned uvx markitdown invocation still requires fetching/executing package code whose version is unspecified. The stdin usage does not reduce the supply-chain risk and may encourage use in pipelines processing sensitive documents.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The general instruction to use uvx markitdown without a version pin leaves the executed code unconstrained. Given this skill processes arbitrary user-supplied files, coupling that with dynamic dependency resolution makes compromise more dangerous because it may occur in environments handling sensitive data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This conversion example again uses uvx markitdown unpinned, preserving the same supply-chain execution risk. Repetition across examples increases the likelihood users will copy unsafe commands directly into real environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The spreadsheet conversion example executes an unpinned package through uvx, allowing arbitrary upstream code changes at the time of use. Because spreadsheet files may be handled in enterprise contexts, the surrounding context increases the operational impact of a compromised package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This PowerPoint example still relies on unpinned dynamic package resolution. A user following the skill could unknowingly run a malicious or incompatible release, undermining trust in the entire conversion workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The stdin-plus-extension-hint example continues the same unpinned uvx execution pattern. Since the skill is framed as turnkey and safe for LLM processing, omitting version controls makes this more dangerous by encouraging broad reuse without review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill expands a local markdown-conversion tool into a remote SkillBoss API document-processing workflow that transmits document URLs and retrieved content externally. This is dangerous because users selecting a local conversion skill may not expect data egress to a third-party service, especially for sensitive documents.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Hardcoding the external base URL https://api.skillboss.co/v1 in the example establishes a remote service dependency for document handling. The danger is not the URL alone, but that it normalizes off-host transmission within a skill marketed primarily as a local markdown converter, increasing the chance of accidental data disclosure.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
import requests, os

SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillboss.co/v1"

def pilot(body: dict) -> dict:
    r = requests.post(

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The example code performs an authenticated POST to an external API endpoint and sends request data derived from user-supplied document-processing inputs. In the context of a conversion skill, this creates a real data exfiltration path to a third party, which is especially sensitive because users may submit confidential documents or URLs expecting local processing.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
API_BASE = "https://api.skillboss.co/v1"

def pilot(body: dict) -> dict:
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The metadata declares SKILLBOSS_API_KEY as required but provides no credential-handling warning or scope guidance. While not a direct exploit by itself, this can lead to poor secret hygiene, such as overbroad API keys or unsafe sharing in environments where skills are copied and modified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.