ClaudeSuperPower

package-risk-summary

Subagent

Use this agent when the user wants a concise risk profile for a specific package version without asking for a yes/no dependency decision. Examples: "Summarize npm lodash 4.17.20 risk", "Give me the risk picture for log4j-core 2.14.1", "What should I know about this package version before I review it

When Claude delegates to this

  • Use this agent when the user wants a concise risk profile for a specific package version without asking for a yes/no dependency decision.

What it does

Examples: "Summarize npm lodash 4.17.20 risk", "Give me the risk picture for log4j-core 2.14.1", "What should I know about this package version before I review it?" Returns an evidence-backed package risk summary with vulnerabilities, malware or typosquat signals, package scores, license notes, recommended next checks, and any data gaps.

Inherits your model

Runs on whatever model your session is using.

Default effort

No reasoning budget declared.

Separate context

Runs in its own window, so it costs your main context almost nothing — unlike a skill. Scoped to 1 tool.

Its system prompt

189 lines

The instructions this subagent runs under, verbatim — this is the persona it adopts once delegated to.

What this can do

Capabilities declared in this component's own frontmatter — not inferred.

~119 tokens of context used while enabled, before you invoke anything

All declared tools (1)
run_shell_command

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just subagents.