context-optimizer

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
hooks/request-after.js

This module is a telemetry/analytics hook that forwards compression metrics, identifiers (agentWallet), and potentially sensitive original prompt/context to an external optimizer interface without sanitization or consent. The file contains no direct malicious constructs (no exec/eval, no hard-coded credentials), but it poses a privacy/data-leak risk depending on the behavior of the optimizer backend. Recommend reviewing getContextOptimizer() and the optimizer sinks to verify destinations, transport security, storage policies, and adding redaction, anonymization (hashing of agentWallet), and consent controls before sending original contexts that may contain secrets.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/AtlasPA%2Fopenclaw-context-optimizer%2Fcontext-optimizer%2F@bc75d5c52f1ae2b6ae43db690f3ab1a2380ee161
Security Audit — socket — context-optimizer