mmk-shared

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with a CLI foundation skill, but install trust is weakened because the exact npm package provenance could not be verified and the package uses a mutable beta tag. The configurable server endpoint also broadens data-flow risk, though there is no clear evidence of credential theft, covert behavior, or unrelated access.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:24 PM
Package URL
pkg:socket/skills-sh/magic-meal-kits%2Fmmk-skills%2Fmmk-shared%2F@0d683372ecdabaab3627b2c22b1bc3272ba74204