Shadows Context Optimizer

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent instruction-only context optimization skill with no code, install steps, credentials, persistence, or network access, though it can change how sparingly the agent searches, reads, and delegates work.

This skill appears safe to install as an instruction-only efficiency aid. Use it when you want shorter responses and lower context usage, but disable or override its search limits and subagent delegation when working on sensitive projects or tasks that require exhaustive analysis.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If invoked during a task that needs exhaustive investigation, the agent may prioritize efficiency over completeness.

Why it was flagged

The skill intentionally changes the agent's search behavior as part of token optimization.

Skill content
"3-search maximum" — "never use more than 3 search tools for one query"
Recommendation

Use this skill when context pressure matters; tell the agent to ignore the search limit when thoroughness is more important.

What this means

For sensitive projects, delegated subagents may see parts of the task context or codebase.

Why it was flagged

The skill advises delegating exploration to subagents, which may pass task context or workspace details across agent boundaries depending on the host environment.

Skill content
"Spawn a subagent for codebase exploration" and "Multiple subagents can run in parallel for independent queries"
Recommendation

Use subagent delegation only within trusted agent/workspace boundaries, or instruct the agent not to delegate when handling sensitive material.

What this means

A user might underestimate the operational tradeoff between token efficiency and completeness.

Why it was flagged

The absolute safety wording is stronger than the artifact can prove because the skill still changes agent behavior and recommends subagent/file-reading strategies.

Skill content
"Zero risk profile."
Recommendation

Treat the skill as low-risk and instruction-only, but not literally risk-free; review its behavior if accuracy or exhaustive search is important.