mmk-paymint-send

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose and command usage are coherent for invoicing, but the skill’s trust model is weak: it relies on an unverifiable external `mmk` CLI, likely uses shared credentials through that CLI, and performs a real-world financial action. No direct evidence of malware or overt exfiltration appears in this skill text, but the dependency and credential-forwarding risk are disproportionate enough to classify it as suspicious/high risk.

Confidence: 82%Severity: 84%
Audit Metadata
Analyzed At
Mar 17, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/magic-meal-kits%2Fmmk-skills%2Fmmk-paymint-send%2F@240482f509e3dd726dc078677f42e9edfe24dbbb