github.com / microsoft
microsoft/ markitdown
Python·165 files·commit 9dc0d65·scanned 12d ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — microsoft is a verified organization — findings likely false positives
verdict accurate?
Verified organization
42% file coverage
threat-state: lowlive
FINDINGS ░▒▓
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.packages/markitdown/src/markitdown/_markitdown.py+3
warningHigh-entropy string literalsFound 11 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.packages/markitdown/src/markitdown/converter_utils/docx/pre_process.py+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.packages/markitdown-ocr/tests/test_pdf_converter.py+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
70 files scanned @ 9dc0d65 | 8/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain0
owasp / injection0
telemetry
files 70/165rules hit 4engine v5commit 9dc0d65
github
microsoft/markitdown
Python tool for converting files and office documents to Markdown.
176165
12920
662d
165 files
70 scanned(42%)
9dc0d65
architecture░▒▓
entry (0) flagged (7) pkg (96)
164 nodes · 385 edgesscroll to zoom · click node to jump to finding