Forensify — AI Agent Stack Self-Audit
A read-only auditor that inventories the skills, MCP servers, hooks, plugins and credential files already installed on your machine and reports the risk surface.
Security & ReviewIntermediate★ 182⑂ 29AI score 9/10Last updated: Sep 27, 2026
What it does
- Auto-detects Claude Code, Codex, OpenClaw, NanoClaw and Cursor, then walks every surface — skills, MCP servers, hooks, plugins, slash commands, memory files (CLAUDE.md, AGENTS.md, SOUL.md) and credential files — into a deterministic JSON inventory with no model calls.
- Splits findings across six risk domains (skills / MCP / hooks & auto-execution / plugin trust chain / commands-config-memory / credentials & permissions) and renders both
briefing.mdandbriefing.json. - Credentials are handled by metadata only: file mode and permissions, auth_mode (apiKey = higher risk), token staleness. Values are never read.
- Surfaces cross-ecosystem issues you can only see when several agent stacks coexist: colliding skill names, duplicate or contradictory AGENTS.md files, and known upstream bugs where one tool overwrites another's tokens.
- Treats every scanned file as hostile data, adds suppression detection so an injected sub-agent cannot report an empty clean bill of health, and writes only to
~/.cache/forensify/runs/.
Who it's for
- Anyone who has accumulated skills, plugins and MCP servers and lost track of what is installed.
- People who want to verify auto-execution surfaces such as hooks or Cursor's
beforeShellExecution. - Users running Claude Code alongside Codex or Cursor who hit config or token conflicts.
- Anyone auditing what is already installed, rather than vetting third-party code before install.
Examples
- "Audit my whole agent setup" → detects all ecosystems and produces a risk briefing.
forensify --inventory→ zero-LLM JSON inventory you can pipe into other tooling.forensify --domains skills,credentials→ quick post-install check for prompt-injection risk and loose credential file permissions.forensify --include-shadows→ also scans backups, caches and session databases for stale tokens or orphaned skill versions.
· · · Install guide · · ·
Try it now, no install
Paste this into Claude to use the skill without installing anything.
Read the instructions in this file and follow them to help me: https://raw.githubusercontent.com/alexgreensh/repo-forensics/HEAD/plugins/repo-forensics/skills/forensify/SKILL.md What I want: (describe your task here)
If Claude can't open the link, open it yourself and paste the contents instead.
↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.
Install in the Claude app (no terminal)
- Download the ZIP with the button below.
- In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
- Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
Install in Claude Code
Let Claude do it — paste this into Claude Code
Install the skill I found on Claude Skill Mart. Copy the plugins/repo-forensics/skills/forensify folder from the GitHub repo alexgreensh/repo-forensics into my ~/.claude/skills/forensify/. When it's done, tell me in one line what this skill can do.
Install with a command instead
git clone https://github.com/alexgreensh/repo-forensics.git && mkdir -p ~/.claude/skills && cp -r repo-forensics/plugins/repo-forensics/skills/forensify ~/.claude/skills/⚠ This is a third-party skill. Check the source repository before installing.
- Open a terminal.
- Clone the repo:
git clone https://github.com/alexgreensh/repo-forensics.git - Create the skills folder:
mkdir -p ~/.claude/skills - Copy the skill:
cp -r repo-forensics/plugins/repo-forensics/skills/forensify ~/.claude/skills/ - Confirm the
scripts/,orchestrator/,config/anddomains/subfolders came along withSKILL.md— the skill will not run without them. - Check Python 3 is available:
python3 --version - Restart Claude Code and ask: "use forensify to audit my agent stack".
- For a first run, try
forensify --inventory(read-only, no model calls) to see the output shape before running the full audit.
View source on GitHub ↗License: NOASSERTION