Claude Skill MartBrowse skillsQuick linesLearn by videoTerminal guideWhat is a Skill?
← Back to list

Forensify — AI Agent Stack Self-Audit

A read-only auditor that inventories the skills, MCP servers, hooks, plugins and credential files already installed on your machine and reports the risk surface.

Security & ReviewIntermediate★ 182⑂ 29AI score 9/10Last updated: Sep 27, 2026

What it does

  • Auto-detects Claude Code, Codex, OpenClaw, NanoClaw and Cursor, then walks every surface — skills, MCP servers, hooks, plugins, slash commands, memory files (CLAUDE.md, AGENTS.md, SOUL.md) and credential files — into a deterministic JSON inventory with no model calls.
  • Splits findings across six risk domains (skills / MCP / hooks & auto-execution / plugin trust chain / commands-config-memory / credentials & permissions) and renders both briefing.md and briefing.json.
  • Credentials are handled by metadata only: file mode and permissions, auth_mode (apiKey = higher risk), token staleness. Values are never read.
  • Surfaces cross-ecosystem issues you can only see when several agent stacks coexist: colliding skill names, duplicate or contradictory AGENTS.md files, and known upstream bugs where one tool overwrites another's tokens.
  • Treats every scanned file as hostile data, adds suppression detection so an injected sub-agent cannot report an empty clean bill of health, and writes only to ~/.cache/forensify/runs/.

Who it's for

  • Anyone who has accumulated skills, plugins and MCP servers and lost track of what is installed.
  • People who want to verify auto-execution surfaces such as hooks or Cursor's beforeShellExecution.
  • Users running Claude Code alongside Codex or Cursor who hit config or token conflicts.
  • Anyone auditing what is already installed, rather than vetting third-party code before install.

Examples

  1. "Audit my whole agent setup" → detects all ecosystems and produces a risk briefing.
  2. forensify --inventory → zero-LLM JSON inventory you can pipe into other tooling.
  3. forensify --domains skills,credentials → quick post-install check for prompt-injection risk and loose credential file permissions.
  4. forensify --include-shadows → also scans backups, caches and session databases for stale tokens or orphaned skill versions.

· · · Install guide · · ·

Try it now, no install

Paste this into Claude to use the skill without installing anything.

Read the instructions in this file and follow them to help me:
https://raw.githubusercontent.com/alexgreensh/repo-forensics/HEAD/plugins/repo-forensics/skills/forensify/SKILL.md

What I want: (describe your task here)

If Claude can't open the link, open it yourself and paste the contents instead.

↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.

Install in the Claude app (no terminal)
  1. Download the ZIP with the button below.
  2. In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
  3. Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
↓ Download ZIP
Install in Claude Code

Let Claude do it — paste this into Claude Code

Install the skill I found on Claude Skill Mart.
Copy the plugins/repo-forensics/skills/forensify folder from the GitHub repo alexgreensh/repo-forensics into my ~/.claude/skills/forensify/.
When it's done, tell me in one line what this skill can do.

Install with a command instead

git clone https://github.com/alexgreensh/repo-forensics.git && mkdir -p ~/.claude/skills && cp -r repo-forensics/plugins/repo-forensics/skills/forensify ~/.claude/skills/

⚠ This is a third-party skill. Check the source repository before installing.

  1. Open a terminal.
  2. Clone the repo: git clone https://github.com/alexgreensh/repo-forensics.git
  3. Create the skills folder: mkdir -p ~/.claude/skills
  4. Copy the skill: cp -r repo-forensics/plugins/repo-forensics/skills/forensify ~/.claude/skills/
  5. Confirm the scripts/, orchestrator/, config/ and domains/ subfolders came along with SKILL.md — the skill will not run without them.
  6. Check Python 3 is available: python3 --version
  7. Restart Claude Code and ask: "use forensify to audit my agent stack".
  8. For a first run, try forensify --inventory (read-only, no model calls) to see the output shape before running the full audit.
View source on GitHub ↗License: NOASSERTION