MarkdownifySAFE
A Model Context Protocol server for converting almost anything to Markdown
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Markdownify is a Model Context Protocol (MCP) server that converts various file types and web content to Markdown format. It provides a set of tools to transform PDFs, images, audio files, web pages, and more into easily readable and shareable Markdown text.
Features
- Convert multiple file types to Markdown:
- Images
- Audio (with transcription)
- DOCX
- XLSX
- PPTX
- Convert web content to Markdown:
- YouTube video transcripts
- Bing search results
- General web pages
- Retrieve existing Markdown files
Getting Started
- Clone this repository
- Install dependencies:
bun install
The preinstall step creates a Python virtual environment at .venv and installs markitdown[all].
- Build the project:
bun run build
- Start the server:
bun start
Development
- Use
bun run devto start the TypeScript compiler in watch mode - Modify
src/server.tsto customize server behavior - Add or modify tools in
src/tools.ts
Usage with Desktop App
To integrate this server with a desktop app, add the following to your app's server configuration:
{
"mcpServers": {
"markdownify": {
"command": "node",
"args": [
"{ABSOLUTE PATH TO FILE HERE}/dist/index.js"
]
}
}
}Environment variables
All paths default to sensible values; override only when the defaults don't fit your install layout.
44138f1e0b77OBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-markdownify-server -- npx -y [email protected]
{
"mcpServers": {
"mcp-markdownify-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (11)
11 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
audio-to-markdown | read | Convert an audio file to markdown, including transcription if possible |
bing-search-to-markdown | read | Convert a Bing search results page to markdown |
docx-to-markdown | read | Convert a DOCX file to markdown |
get-markdown-file | read | Get a markdown file by absolute file path |
git-repo-to-markdown | read | Convert a git repository into a single markdown document containing the file tree and source code. Supports GitHub URLs and shorthand (e.g. |
image-to-markdown | read | Convert an image to markdown, including metadata and description |
pdf-to-markdown | read | Convert a PDF file to markdown |
pptx-to-markdown | read | Convert a PPTX file to markdown |
webpage-to-markdown | read | Convert a webpage to markdown |
xlsx-to-markdown | read | Convert an XLSX file to markdown |
youtube-to-markdown | read | Convert a YouTube video to markdown, including transcript if available |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
expect(() => validateUrl("http://169.254.169.254")).toThrow(expect(() => validateUrl("http://192.168.1.1")).toThrow(expect(() => validateUrl("http://127.0.0.1")).toThrow(expect(() => validateUrl("http://169.254.169.254")).toThrow(@modelcontextprotocol/sdk, private-ip, repomix, zod, @types/node, typescript
logo.jpg
Gates applied: no_behavioural_pass.
44138f1e0b77full audit observations/trust-audit/mcp-server/zcaceres__markdownify.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 44138f1e0b77 | SAFE | B | 89 | source changed, verdict held |
Questions
What is the Markdownify MCP server?
A Model Context Protocol server for converting almost anything to Markdown
What tools does Markdownify expose?
11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Markdownify safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Markdownify need?
No credential environment variables were found in its source, so it appears to need none.
How does Markdownify run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-markdownify-server at 1.1.0.
How current is this page?
The grade is for one exact copy of the source (44138f1e0b77), read on 2026-09-22. The repository is watched and re-audited when it changes.