context-optimizer

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
hooks/request-after.js

This module is a telemetry/analytics hook that forwards compression metrics, identifiers (agentWallet), and potentially sensitive original prompt/context to an external optimizer interface without sanitization or consent. The file contains no direct malicious constructs (no exec/eval, no hard-coded credentials), but it poses a privacy/data-leak risk depending on the behavior of the optimizer backend. Recommend reviewing getContextOptimizer() and the optimizer sinks to verify destinations, transport security, storage policies, and adding redaction, anonymization (hashing of agentWallet), and consent controls before sending original contexts that may contain secrets.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/AtlasPA%2Fopenclaw-context-optimizer%2Fcontext-optimizer%2F@bc75d5c52f1ae2b6ae43db690f3ab1a2380ee161