Security audit
Markitdown
Security checks across malware telemetry and agentic risk
Overview
This skill is a documentation-only guide for using MarkItDown to convert documents and media into Markdown, with its file, network, and package-install behaviors disclosed and aligned with that purpose.
Install only if you are comfortable adding the MarkItDown Python package and optional plugins/tools to your environment. Use it on files and URLs you choose, and avoid untrusted documents or plugins unless you are willing to accept normal document-parser and network-access risks.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
63/63 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
