parley
Warn
Audited by Socket on Aug 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The GitHub review workflow is purpose-aligned, and the intended API target is GitHub, but the skill's core dependency is a locally bootstrapped `scrutiny` binary with unverifiable provenance. Because that binary is central to fetching comments, spawning agents, and performing commit/push/reply actions, the install/execution trust issue is disproportionate enough to make the skill high risk even without confirmed malicious data exfiltration.
Confidence: 84%Severity: 82%
Audit Metadata