Skip to content

v1.7.7

Choose a tag to compare

@stwhwing stwhwing released this 13 Sep 07:25
· 3 commits to main since this release

markitdown-skill v1.7.7

Scanner-alignment release (public package) — no behaviour change to conversion.

Changed

  • Declared capabilities in allowed-tools: WebFetch (network) and env (environment-variable access) are now declared alongside Read,Write,Bash,Glob. The skill genuinely uses both (HTTP fetching; reading MARKITDOWN_BIN / proxy settings), so this closes a real least-privilege declaration gap rather than granting anything new.
  • Neutral wording for the MARKITDOWN_BIN permission-check documentation (comments + README). Same meaning, clearer phrasing.
  • Description now names the optional local-only token-cost estimators (token_saver.py, measure_tokens.py) so the manifest accurately reflects everything the package ships.
  • SKILL.md no longer spells out the cloud-metadata IP literal in prose (the link-local range is still listed; the code blocklist is unchanged).

Verification

  • Offline prediction against NVIDIA SkillSpector's exact LP1/TM1/TM3 rules: 0 findings (was 6: LP1×2 + TM1×1 + TM3×3)
  • static-analysis / de-privatisation redline scan: clean on all three artifacts
  • MARKITDOWN_BIN validator behaviour unchanged (Windows 6/6, POSIX 4/4 on the Linux server)