v1.7.7
markitdown-skill v1.7.7
Scanner-alignment release (public package) — no behaviour change to conversion.
Changed
- Declared capabilities in
allowed-tools:WebFetch(network) andenv(environment-variable access) are now declared alongsideRead,Write,Bash,Glob. The skill genuinely uses both (HTTP fetching; readingMARKITDOWN_BIN/ proxy settings), so this closes a real least-privilege declaration gap rather than granting anything new. - Neutral wording for the
MARKITDOWN_BINpermission-check documentation (comments + README). Same meaning, clearer phrasing. - Description now names the optional local-only token-cost estimators (
token_saver.py,measure_tokens.py) so the manifest accurately reflects everything the package ships. - SKILL.md no longer spells out the cloud-metadata IP literal in prose (the link-local range is still listed; the code blocklist is unchanged).
Verification
- Offline prediction against NVIDIA SkillSpector's exact LP1/TM1/TM3 rules: 0 findings (was 6: LP1×2 + TM1×1 + TM3×3)
static-analysis/ de-privatisation redline scan: clean on all three artifacts- MARKITDOWN_BIN validator behaviour unchanged (Windows 6/6, POSIX 4/4 on the Linux server)