markdown-new

Warn

Audited by Socket on Sep 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior matches its stated purpose, but it routes conversions, crawl jobs, and optional file uploads through markdown.new rather than Cloudflare's documented official API endpoints. That makes the main concern data-flow/intermediary trust, not malware: proportionate capability, no installer or credential harvesting, but medium risk if users upload sensitive files or rely on implied Cloudflare ownership.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 25, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/jpcaparas%2Fskills%2Fmarkdown-new%2F@330ed387019aed5a80da20b0fc25e9364675db5ec6d4270037fda8b5e13a4d74
Security Audit — socket — markdown-new