THRONE
See report Verify server

registry / record

github.com/zcaceres/markdownify-mcp

github / sealed 2026-06-16 / No. 1405c343

Does github.com/zcaceres/markdownify-mcp MCP work in Claude Code and Cursor? Throne executed github.com/zcaceres/markdownify-mcp mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: fit. Is github.com/zcaceres/markdownify-mcp mcp safe? Static security scan: 2 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry github.com/zcaceres/markdownify-mcp sealed
receiptsealed evidence
scan id
1405c34304494de7b72d49fe1a99ad9c
target
https://github.com/zcaceres/markdownify-mcp
sealed at
2026-06-16 17:09:39Z
evidence hash
sha256:7ab21ce746427406b523d554a04f1fb112917ec3f308fb45c4d5a9e3b985f81c
01connectPASS710ms

initialize ok: server mcp-markdownify-server 0.1.0, negotiated protocolVersion 2025-11-25, capabilities ['tools']

02discoverPASS5ms

supported: tools/list (11 tools); method not found (tolerated): resources/list, prompts/list

03validate_schemasPASS13ms

all 11 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS9.2s

called 10 of 10 tools (cap 10, strategy=serial): 0 ok, 10 returned tool-level errors (expected for synthesized args)

05error_handlingPASS4.6s

structured error responses, connection survived, wrong_type_args: audio-to-markdown:error(-32603); bing-search-to-markdown:error(-32603); docx-to-markdown:error(-32603); get-markdown-file:error(-32603); git-repo-to-markdown:error(-32603); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: accepted (returned result); recovery: accepted (returned result); cancellation: accepted (returned result); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingNOT_APPLICABLE0ms

no streaming-capable tool declared by this server

07resource_lifecycleNOT_APPLICABLE2ms

resources capability not declared

08concurrent_callsWARN1.7s

ladder 1 overlapping audio-to-markdown calls: max_observed_stable_concurrency=1; all ids answered exactly once, but every call returned an error (tool-level isError result), the tool may need runtime dependencies this sandbox does not provide

09reconnectPASS765ms

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

01connectPASS1.5s

initialize ok: server mcp-markdownify-server 0.1.0, negotiated protocolVersion 2025-11-25, capabilities ['tools'] [request_strategy=pipelined, connection_count=2, second connection established]

02discoverPASS6ms

supported: tools/list (11 tools); method not found (tolerated): resources/list, prompts/list; notes: connection 2 confirms 11 tools

03validate_schemasPASS12ms

all 11 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS3.3s

called 10 of 10 tools (cap 10, strategy=pipelined): 0 ok, 10 returned tool-level errors (expected for synthesized args)

05error_handlingPASS4.6s

structured error responses, connection survived, wrong_type_args: audio-to-markdown:error(-32603); bing-search-to-markdown:error(-32603); docx-to-markdown:error(-32603); get-markdown-file:error(-32603); git-repo-to-markdown:error(-32603); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: accepted (returned result); recovery: accepted (returned result); cancellation: accepted (returned result); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingNOT_APPLICABLE0ms

no streaming-capable tool declared by this server

07resource_lifecycleNOT_APPLICABLE2ms

resources capability not declared

08concurrent_callsWARN14.9s

ladder 1/2/4/6 overlapping audio-to-markdown calls: max_observed_stable_concurrency=4; degraded above that, level 6: id mapping broken, 6 distinct request ids, 0 matched exactly once (expected 6)

09reconnectPASS10.2s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 2 finding(s) (1 high) / review recommended
HIGH/CRITICAL findings block clean ship. Review before shipping.
HIGHTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"preinstall" runs arbitrary code on every npm install: 'node preinstall.js'

markdownify-mcp-HEAD/package.json
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

markdownify-mcp-HEAD/scripts/docker-smoke-test.sh:23
VERDICT: FIT (HIGH/CRITICAL findings, review before shipping)14 of 18 steps exercised across 2 clientsSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility: 0 fail / 2 warn (14 of 18 steps exercised across 2 clients) / security: review, 2 finding(s), 1 high [SECURITY: 1 high/critical finding(s) block clean ship]sealed by THRONE / No. 1405c343 / 2026-06-16
scopeattestation tuple
target
https://github.com/zcaceres/markdownify-mcp github
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
14 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 17:09:39Z
evidence hash
sha256:7ab21ce746427406b523d554a04f1fb112917ec3f308fb45c4d5a9e3b985f81c
valid until
2026-09-14
THRONE: FITwear the crown

paste this in your README. it renders the live verdict and links back to this record. if a release ever breaks the verdict, the badge says so on its own.

[![THRONE: FIT](https://api.usethrone.dev/api/badge/https%3A%2F%2Fgithub.com%2Fzcaceres%2Fmarkdownify-mcp)](https://usethrone.dev/server/zcaceres-markdownify-mcp)
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.