markitdown-cli

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the markitdown Python package and various extras (e.g., pdf, az-doc-intel) from standard package registries.
  • [COMMAND_EXECUTION]: The documentation includes numerous shell command examples and bash scripts for automating document conversion, batch processing using find and xargs, and integrating with standard Linux utilities like grep and jq.
  • [DATA_EXFILTRATION]: Instructions are provided for configuring Azure Document Intelligence and Content Understanding endpoints. This involves transmitting document data to external cloud services. The skill explicitly identifies and warns about the risk of Server-Side Request Forgery (SSRF) when the tool is used to process remote URIs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 10:04 AM
Security Audit — agent-trust-hub — markitdown-cli