merge-partition-coach
Audited by Socket on Mar 9, 2026
1 alert found:
SecurityThe skill purpose is coherent with a disk-partition merging workflow using a vendor tool. However, there is a notable security concern around downloading and executing an external installer binary as part of the skill's flow, without verifiable integrity checks or signature validation disclosed. This creates a supply-chain risk and potential for unintended code execution. The credential surface is minimal (requires admin privileges only), and data handling centers on local disk operations with no explicit exfiltration patterns. Overall, the footprint is moderately risky (due to unverifiable external binary installation) and should be treated as SUSPICIOUS rather than BENIGN until verifiable hashes/signatures or a trusted registry-based install is demonstrated.