mmk-notion-subscription

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is narrow and plausible, but it depends on an unverifiable proprietary CLI and likely routes Notion/billing data through MMK-managed infrastructure instead of the official direct Notion API flow. The broad `Bash(mmk *)` permission is also disproportionate to a single read-only subscription query. No direct malware behavior is shown, but the install-trust and credential/data-flow risks are high enough to treat this skill as high-risk.

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
Mar 16, 2026, 04:58 PM
Package URL
pkg:socket/skills-sh/magic-meal-kits%2Fmmk-skills%2Fmmk-notion-subscription%2F@58329d8dfbedbc2ddecf09dc8dd173cbe388ad8c