mmk-threads-posts

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated capability is coherent with a Threads-posts skill, and the described data flow matches official Threads API concepts. However, the skill's trust boundary depends on an unverifiable `mmk` CLI and a hidden shared auth skill, and the wildcard `mmk *` shell permission is broader than necessary. Main concern is install/provenance uncertainty, not confirmed malicious behavior.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Mar 17, 2026, 03:28 PM
Package URL
pkg:socket/skills-sh/magic-meal-kits%2Fmmk-skills%2Fmmk-threads-posts%2F@f4613b876e12077d19455ff6082263ef84542166