mmk-notion-user
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s visible commands are narrow and read-only, but its real footprint depends on an unverifiable `mmk` CLI and a third-party MMK service that appears to proxy Notion access and receive Notion token/session headers. That combination is internally inconsistent with a simple Notion user lookup skill and triggers the mandatory high-risk floor for unverifiable credential-handling dependencies.
Confidence: 86%Severity: 86%
Audit Metadata