synthadocBLOCK
Synthadoc: An open-source LLM knowledge compilation engine that turns raw documents into structured, local-first wikis. A transparent, human-readable alternative to traditional RAG, which can be self-managed and self-improved without the use of any tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
.-+###############+-. .## ##. ## .----. .----. ## ## /######\ /######\ ## ## |######| |######| ## ## | [SD] | | wiki | ## ## |######| |######| ## ## \######/ \######/ ## ## '----' '----' ## '## ##' '-+###############+-' S Y N T H A D O C Community Edition v1.4.1 ──────────────────────────────── Domain-agnostic LLM wiki engine
a04ca790db61OBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
pip install synthadoc
git clone https://github.com/axoviq-ai/synthadoc.git
pip install -e ".[dev]"
npm install # first time only, or after package.json changes
claude mcp add --transport sse synthadoc-my-market-wiki http://127.0.0.1:7070/mcp/sse
pip install synthadoc
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| claude-desktop | mentioned | |
| codex | mentioned | |
| cursor | mentioned | |
| gemini-cli | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: docx
version: "1.0"
description: Extract text from Microsoft Word documents
entry:
script: scripts/main.py
class: DocxSkill
triggers:
extensions:
- ".docx"
intents:
- "word document"
- "docx"
requires:
- python-docx
author: axoviq.com
license: AGPL-3.0-or-later
---
# DOCX Skill
Extracts paragraph text from `.docx` files using `python-docx`.
## Setup
```bash
pip install python-docx
```
## Standalone usage
```python
import asyncio
from synthadoc.skills.docx.scripts.main import DocxSkill
skill = DocxSkill()
async def main():
result = await skill.extract("/path/to/document.docx")
print(result.text) # all paragraphs joined as plain text
asyncio.run(main())
```
## When this skill is used
- Source path ends with `.docx`
- User intent contains: `word document`, `docx`Trust audit
BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
In order to be iterable, non-array objects must have a [Symbol.iterator]() method.`)}function at(r,e){return Tv(r)||_v(r,e)||bo(r,e)||Pv()}function An(r){return kv(r)||Sv(r)||bo(r)||Lv()}function Bv(r# Synthadoc
# Synthadoc
# Synthadoc — Design Document
# Synthadoc User Quick-Start Guide
deep-learning-concepts.pptx
model-capabilities-comparison.xlsx
computing-pioneers-timeline.xlsx
cs-milestones-overview.pptx
# SPDX-License-Identifier: AGPL-3.0-or-later
return text.lstrip("")# SPDX-License-Identifier: AGPL-3.0-or-later
# SPDX-License-Identifier: AGPL-3.0-or-later
# SPDX-License-Identifier: AGPL-3.0-or-later
module = importlib.import_module(module_path)
return slug or "page-" + hashlib.md5(title.encode()).hexdigest()[:8]
store.write_page("../../etc/passwd", "# evil", {})text='{"entities": [], "concepts": [], "tags": [], "create": ["../../evil"]}',The server binds to `http://127.0.0.1:7070` (localhost-only). Leave it running while you work — the Obsidian plugin, CLI ingest commands, and query commands all talk to it.
claude mcp add --transport sse synthadoc-my-market-wiki http://127.0.0.1:7070/mcp/sse
curl http://127.0.0.1:7070/health
The server binds to `http://127.0.0.1:7070` (localhost-only). Leave it running while you work — the Obsidian plugin, CLI ingest commands, and query commands all talk to it.
claude mcp add --transport sse synthadoc-my-market-wiki http://127.0.0.1:7070/mcp/sse
source.write_text("normaltext", encoding="utf-8")text, warnings = sanitize("normalevil")Gates applied: no_behavioural_pass.
a04ca790db61full audit observations/trust-audit/skill/axoviq-ai__synthadoc.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a04ca790db61 | BLOCK | F | 50 | first audit |
Questions
What does the synthadoc skill do?
Synthadoc: An open-source LLM knowledge compilation engine that turns raw documents into structured, local-first wikis. A transparent, human-readable alternative to traditional RAG, which can be self-managed and self-improved without the use of any tools.
Is synthadoc safe to install?
No — not without reading the findings first. The audit graded it F (50/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can synthadoc access on my machine?
The audit observed that it runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.
Which assistants does synthadoc work with?
Its documentation mentions claude-code, claude-desktop, codex, cursor and gemini-cli. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (a04ca790db61), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.