markdownify-mcp is a local MCP server that turns PDFs, Word and PowerPoint files, images, HTML, and audio into Markdown so an agent can read them. It runs over stdio, has no authentication, ships only as source (no npm package), and leans on helper binaries. TrustedMCP grades it D — the shell-out path is the problem, not the feature set.
What it connects
- Converts local files or URLs — PDF,
.docx,.pptx,.xlsx, images, HTML, plus audio transcription — into a single Markdown string. - Returns the text into the model context. There is no write path back to your files.
- Under the hood it invokes helper tools (a Python converter stack, and
ffmpeg/transcription for audio) as child processes.
Setup
There is no published package, so install from source:
git clone https://github.com/zcaceres/markdownify-mcp
cd markdownify-mcp
pnpm install && pnpm build
Claude Desktop / Claude Code config:
{
"mcpServers": {
"markdownify": {
"command": "node",
"args": ["/abs/path/to/markdownify-mcp/dist/index.js"]
}
}
}
Cursor (.cursor/mcp.json) takes the same command / args. The server needs
Python and ffmpeg on PATH for the full converter set.
Security notes
The reason this is a D: the server passes file paths and content to helper binaries as child processes. Shell-out on model-reachable input is the exact injection surface flagged across the MCP ecosystem — a crafted filename or document can influence what actually runs. There is also no auth (expected for a local stdio tool) and no meaningful commit activity for months, so a fix is unlikely to arrive soon.
Run it only against files you control, inside a container with no credentials to anything that matters, or wait for a maintained fork. See MCP security best practices and how TrustedMCP scores servers. Full breakdown on the markdownify-mcp listing.
Need this built and hardened for you?
We build custom, security-reviewed MCP servers. Tell us what you need an agent to reach.
Start a conversation