ClaudeSuperPower

malware-response

Subagent

Use this agent when a customer needs rapid read-only response to a software supply-chain malware incident. It gathers or ingests current malware intelligence, normalizes affected package and version evidence, and correlates that evidence against Endor Labs tenant package inventory across a namespace

When Claude delegates to this

  • Use this agent when a customer needs rapid read-only response to a software supply-chain malware incident.

What it does

It gathers or ingests current malware intelligence, normalizes affected package and version evidence, and correlates that evidence against Endor Labs tenant package inventory across a namespace and child namespaces. It reports confirmed exposure, possible exposure, unaffected scope, indicators of compromise, remediation guidance, and future action contracts without mutating Endor Labs or source systems.

Inherits your model

Runs on whatever model your session is using.

Default effort

No reasoning budget declared.

Separate context

Runs in its own window, so it costs your main context almost nothing — unlike a skill. Scoped to 1 tool.

Its system prompt

149 lines

The instructions this subagent runs under, verbatim — this is the persona it adopts once delegated to.

What this can do

Capabilities declared in this component's own frontmatter — not inferred.

~128 tokens of context used while enabled, before you invoke anything

All declared tools (1)
run_shell_command

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just subagents.