Atlas / MCP servers / zcaceres / Markdownify

MarkdownifySAFE

mcp/zcaceres/markdownify

A Model Context Protocol server for converting almost anything to Markdown

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
11 11r · 0w · 0d
Transport
stdio
License
MIT
Stars
2,996
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Markdownify is a Model Context Protocol (MCP) server that converts various file types and web content to Markdown format. It provides a set of tools to transform PDFs, images, audio files, web pages, and more into easily readable and shareable Markdown text.

Features

  • Convert multiple file types to Markdown:
  • PDF
  • Images
  • Audio (with transcription)
  • DOCX
  • XLSX
  • PPTX
  • Convert web content to Markdown:
  • YouTube video transcripts
  • Bing search results
  • General web pages
  • Retrieve existing Markdown files

Getting Started

  1. Clone this repository
  2. Install dependencies:
bun install

The preinstall step creates a Python virtual environment at .venv and installs markitdown[all].

  1. Build the project:
bun run build
  1. Start the server:
bun start

Development

  • Use bun run dev to start the TypeScript compiler in watch mode
  • Modify src/server.ts to customize server behavior
  • Add or modify tools in src/tools.ts

Usage with Desktop App

To integrate this server with a desktop app, add the following to your app's server configuration:

{
"mcpServers": {
"markdownify": {
"command": "node",
"args": [
"{ABSOLUTE PATH TO FILE HERE}/dist/index.js"
]
}
}
}

Environment variables

All paths default to sensible values; override only when the defaults don't fit your install layout.

Read from source at commit 44138f1e0b77OBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-markdownify-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-markdownify-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
audio-to-markdownreadConvert an audio file to markdown, including transcription if possible
bing-search-to-markdownreadConvert a Bing search results page to markdown
docx-to-markdownreadConvert a DOCX file to markdown
get-markdown-filereadGet a markdown file by absolute file path
git-repo-to-markdownreadConvert a git repository into a single markdown document containing the file tree and source code. Supports GitHub URLs and shorthand (e.g.
image-to-markdownreadConvert an image to markdown, including metadata and description
pdf-to-markdownreadConvert a PDF file to markdown
pptx-to-markdownreadConvert a PPTX file to markdown
webpage-to-markdownreadConvert a webpage to markdown
xlsx-to-markdownreadConvert an XLSX file to markdown
youtube-to-markdownreadConvert a YouTube video to markdown, including transcript if available
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/utils.test.ts:73
expect(() => validateUrl("http://169.254.169.254")).toThrow(
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils.test.ts:61
expect(() => validateUrl("http://192.168.1.1")).toThrow(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils.test.ts:67
expect(() => validateUrl("http://127.0.0.1")).toThrow(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils.test.ts:73
expect(() => validateUrl("http://169.254.169.254")).toThrow(
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, private-ip, repomix, zod, @types/node, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
logo.jpg
logo.jpg
Why it matters. 1495348 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha 44138f1e0b77full audit observations/trust-audit/mcp-server/zcaceres__markdownify.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2244138f1e0b77SAFEB89source changed, verdict held
06

Questions

What is the Markdownify MCP server?

A Model Context Protocol server for converting almost anything to Markdown

What tools does Markdownify expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Markdownify safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Markdownify need?

No credential environment variables were found in its source, so it appears to need none.

How does Markdownify run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-markdownify-server at 1.1.0.

How current is this page?

The grade is for one exact copy of the source (44138f1e0b77), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement