@mohtasham/md-to-docx Security Audit Report
@mohtasham/md-to-docx is an AI agent skill, created by Mohtasham and published at MohtashamMurshid/md-to-docx. ClawSecure audited @mohtasham/md-to-docx across 60 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 23 findings concentrate in Supply Chain, ReDoS and Code Injection, including Vulnerability in next@15.5.22: Next.js: Unauthenticated… and Vulnerability in next@15.5.22: Next.js: Unauthenticated…. 17 were rated high or critical severity.
Is @mohtasham/md-to-docx safe?
ClawSecure audited @mohtasham/md-to-docx and assigned a security score of 0/100 (High Risk), identifying 23 findings across Supply Chain and ReDoS. Review the findings below before installing.
What did ClawSecure find in @mohtasham/md-to-docx?
ClawSecure identified 23 findings in @mohtasham/md-to-docx, concentrated in Supply Chain, ReDoS and Code Injection. 17 were rated high or critical severity. The most severe include Vulnerability in next@15.5.22: Next.js: Unauthenticated… and Vulnerability in next@15.5.22: Next.js: Unauthenticated….
How was @mohtasham/md-to-docx audited?
ClawSecure ran @mohtasham/md-to-docx through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 60 files from MohtashamMurshid/md-to-docx.
What does a score of 0 mean?
ClawSecure assigned @mohtasham/md-to-docx a security score of 0/100, placing it in the High Risk range. This is driven by 23 findings led by Supply Chain that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for @mohtasham/md-to-docx
ClawSecure detected 23 security findings in @mohtasham/md-to-docx, spanning Supply Chain, ReDoS, Code Injection and Permissions Manifest.
- critical · Vulnerability in next@15.5.22: Next.js: Unauthenticated…. Supply Chain finding detected in
package.json. - critical · Vulnerability in next@15.5.22: Next.js: Unauthenticated…. Supply Chain finding detected in
package.json. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
packageRepairs.ts. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
patchPackage.ts. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom: DocType…. Supply Chain finding detected in
package.json. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom:…. Supply Chain finding detected in
package.json. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom: Attribute…. Supply Chain finding detected in
package.json. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom: HTML…. Supply Chain finding detected in
package.json. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom:…. Supply Chain finding detected in
package.json. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom:…. Supply Chain finding detected in
package.json. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom:…. Supply Chain finding detected in
package.json. - high · Vulnerability in @xmldom/xmldom@0.9.10: xmldom: Processing…. Supply Chain finding detected in
package.json.
Showing the 12 highest-severity of 23 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for @mohtasham/md-to-docx
Update and pin dependencies
Fix ReDoS-prone patterns
Eliminate dynamic code execution
Related Security Research
AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on September 11, 2026. @mohtasham/md-to-docx is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.