mmk-notion-emoji
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is narrow and plausible, but the skill relies on an unverifiable external `mmk` CLI with broad execution scope and hidden auth behavior in another skill. No explicit malicious or exfiltration behavior is shown in this excerpt, yet the missing provenance and delegated credential flow make the trust model incomplete and high-risk.
Confidence: 82%Severity: 72%
Audit Metadata