mmk-notion-comment

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The functional scope matches Notion comment management, but trust and data-flow are weaker than they should be: the skill depends on an unverifiable `mmk` CLI, routes operations through an MMK intermediary rather than the official Notion API, and grants broad `mmk *` execution. This is not confirmed malware, but it is a high-risk skill dependency pattern with disproportionate trust in opaque third-party tooling.

Confidence: 82%Severity: 81%
Audit Metadata
Analyzed At
Mar 17, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/magic-meal-kits%2Fmmk-skills%2Fmmk-notion-comment%2F@714d2bc16c8a54492ff28877ce74349b67a63335