md-to-confluence

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/md-to-confluence.py

No overt malware (no backdoor/reverse shell/cryptomining) is present, and network activity is confined to a configured Confluence host. However, the script can upload attachments whose filepaths are derived from unvalidated markdown image references (md_dir / img_path) without preventing path traversal or absolute paths. If an attacker can influence markdown content or the referenced paths, this can lead to exfiltration of arbitrary local files to Confluence as attachments.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:29 AM
Package URL
pkg:socket/skills-sh/qa-aman%2Fclaude-skills%2Fmd-to-confluence%2F@e57071d159c9f6a0d7f67388118e49975d0e428d7591489b160168b46064f23a
Security Audit — socket — md-to-confluence