mmk-notion-user

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s visible commands are narrow and read-only, but its real footprint depends on an unverifiable `mmk` CLI and a third-party MMK service that appears to proxy Notion access and receive Notion token/session headers. That combination is internally inconsistent with a simple Notion user lookup skill and triggers the mandatory high-risk floor for unverifiable credential-handling dependencies.

Confidence: 86%Severity: 86%
Audit Metadata
Analyzed At
Mar 17, 2026, 03:24 PM
Package URL
pkg:socket/skills-sh/magic-meal-kits%2Fmmk-skills%2Fmmk-notion-user%2F@05447cea16b4a980c66205c755b546668397d0ec