Atlas / Skills / axoviq-ai / synthadoc

synthadocBLOCK

skills/axoviq-ai/synthadoc

Synthadoc: An open-source LLM knowledge compilation engine that turns raw documents into structured, local-first wikis. A transparent, human-readable alternative to traditional RAG, which can be self-managed and self-improved without the use of any tools.

Verdict
BLOCK
Grade
F
Trust score
50 /100
Version
1.0
Hosts
5 documented
License
AGPL-3.0
Stars
1,559
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

.-+###############+-.
.##                   ##.
##    .----.   .----.    ##
##    /######\ /######\    ##
##    |######| |######|    ##
##    | [SD] | | wiki |    ##
##    |######| |######|    ##
##    \######/ \######/    ##
##    '----'   '----'    ##
'##                   ##'
'-+###############+-'

S Y N T H A D O C
Community Edition  v1.4.1
────────────────────────────────
Domain-agnostic LLM wiki engine
Read from source at commit a04ca790db61OBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

pip install synthadoc
git clone https://github.com/axoviq-ai/synthadoc.git
pip install -e ".[dev]"
npm install           # first time only, or after package.json changes
claude mcp add --transport sse synthadoc-my-market-wiki http://127.0.0.1:7070/mcp/sse
pip install synthadoc
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
claude-desktopmentioned
codexmentioned
cursormentioned
gemini-climentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: docx
version: "1.0"
description: Extract text from Microsoft Word documents
entry:
  script: scripts/main.py
  class: DocxSkill
triggers:
  extensions:
    - ".docx"
  intents:
    - "word document"
    - "docx"
requires:
  - python-docx
author: axoviq.com
license: AGPL-3.0-or-later
---

# DOCX Skill

Extracts paragraph text from `.docx` files using `python-docx`.

## Setup

```bash
pip install python-docx
```

## Standalone usage

```python
import asyncio
from synthadoc.skills.docx.scripts.main import DocxSkill

skill = DocxSkill()

async def main():
    result = await skill.extract("/path/to/document.docx")
    print(result.text)      # all paragraphs joined as plain text

asyncio.run(main())
```

## When this skill is used

- Source path ends with `.docx`
- User intent contains: `word document`, `docx`
05

Trust audit

BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
synthadoc/data/obsidian-plugin/main.js:5
In order to be iterable, non-array objects must have a [Symbol.iterator]() method.`)}function at(r,e){return Tv(r)||_v(r,e)||bo(r,e)||Pv()}function An(r){return kv(r)||Sv(r)||bo(r)||Lv()}function Bv(r
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README-pypi.md:1
# Synthadoc
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:1
# Synthadoc
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/design.md:1
# Synthadoc — Design Document
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/user-quick-start-guide.md:1
# Synthadoc User Quick-Start Guide
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.binary · CWE-1104
synthadoc/demos/ai-research/raw_sources/deep-learning-concepts.pptx
deep-learning-concepts.pptx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
synthadoc/demos/ai-research/raw_sources/model-capabilities-comparison.xlsx
model-capabilities-comparison.xlsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
synthadoc/demos/history-of-computing/raw_sources/computing-pioneers-timeline.xlsx
computing-pioneers-timeline.xlsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
synthadoc/demos/history-of-computing/raw_sources/cs-milestones-overview.pptx
cs-milestones-overview.pptx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
synthadoc/agents/ingest_agent.py:1
# SPDX-License-Identifier: AGPL-3.0-or-later
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
synthadoc/cli/_utils.py:85
return text.lstrip("")
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
synthadoc/cli/cache.py:1
# SPDX-License-Identifier: AGPL-3.0-or-later
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
synthadoc/cli/candidates.py:1
# SPDX-License-Identifier: AGPL-3.0-or-later
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
synthadoc/cli/install.py:1
# SPDX-License-Identifier: AGPL-3.0-or-later
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_base_agent.py:87
module = importlib.import_module(module_path)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
synthadoc/agents/ingest_agent.py:339
return slug or "page-" + hashlib.md5(title.encode()).hexdigest()[:8]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/security/test_security.py:13
store.write_page("../../etc/passwd", "# evil", {})
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/security/test_security.py:79
text='{"entities": [], "concepts": [], "tags": [], "create": ["../../evil"]}',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README-pypi.md:382
The server binds to `http://127.0.0.1:7070` (localhost-only). Leave it running while you work — the Obsidian plugin, CLI ingest commands, and query commands all talk to it.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README-pypi.md:541
claude mcp add --transport sse synthadoc-my-market-wiki http://127.0.0.1:7070/mcp/sse
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README-pypi.md:1193
curl http://127.0.0.1:7070/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:403
The server binds to `http://127.0.0.1:7070` (localhost-only). Leave it running while you work — the Obsidian plugin, CLI ingest commands, and query commands all talk to it.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:562
claude mcp add --transport sse synthadoc-my-market-wiki http://127.0.0.1:7070/mcp/sse
LOWObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
tests/test_ingest_agent.py:251
source.write_text("normaltext", encoding="utf-8")
LOWObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
tests/test_sanitizer.py:18
text, warnings = sanitize("normalevil")

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a04ca790db61full audit observations/trust-audit/skill/axoviq-ai__synthadoc.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-08a04ca790db61BLOCKF50first audit
07

Questions

What does the synthadoc skill do?

Synthadoc: An open-source LLM knowledge compilation engine that turns raw documents into structured, local-first wikis. A transparent, human-readable alternative to traditional RAG, which can be self-managed and self-improved without the use of any tools.

Is synthadoc safe to install?

No — not without reading the findings first. The audit graded it F (50/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can synthadoc access on my machine?

The audit observed that it runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does synthadoc work with?

Its documentation mentions claude-code, claude-desktop, codex, cursor and gemini-cli. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (a04ca790db61), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement