Repo Forensics
Deep security auditing for git repos, AI skills and MCP servers — 28 scanners covering prompt injection, credential theft, supply-chain IOCs, and actively exploited CVEs.
Security & ReviewIntermediate★ 185⑂ 29AI score 10/10Last updated: Sep 27, 2026
What it does
- Runs 28 scanners (secrets, SAST, dependencies, AST, DAST, archives, bytecode, git forensics, devcontainer, infra…) against a repo, AI skill, or MCP server.
- Detects AI-agent-specific attacks: prompt injection, invisible unicode smuggling, credential exfiltration, persistence, MCP tool poisoning and rug-pull enablers.
- Enriches dependency findings with live OSV data and cross-references CISA KEV — anything actively exploited in the wild is escalated to CRITICAL.
- Flags manifest drift (declared vs actually used deps) and runtime dynamism (time bombs, fetch-then-execute, self-modifying code).
- Emits text/json/summary/sarif with deterministic exit codes (0/1/2/99) for CI gating.
- Scope is stated up front: it does not fix vulnerabilities or run pentests, and skips .7z/.rar/encrypted archives plus Java/Node/wasm bytecode.
Who it's for
- Anyone vetting third-party Claude Code skills, plugins, or MCP servers before installing them.
- Developers and security engineers reviewing supply-chain risk in new dependencies.
- Teams wiring an automated security gate into CI/CD.
- Incident responders hunting compromise artifacts (RAT binaries, C2 persistence, npm cache traces).
Examples
- Pre-install skill vetting:
./scripts/run_forensics.sh ~/Downloads/some-skill --skill-scanruns the faster 18-scanner pass to surface hidden SKILL.md directives or curl-pipe-bash prerequisites. - CI gate:
./scripts/run_forensics.sh . --format json, parse the report and fail the build on CRITICAL (exit code 2). - Incident investigation:
./scripts/run_forensics.sh /path/to/repo --update-iocs --watchpulls fresh IOCs, matches C2 domains and malicious hashes, and alerts on config-file drift.
· · · Install guide · · ·
Try it now, no install
Paste this into Claude to use the skill without installing anything.
Read the instructions in this file and follow them to help me: https://raw.githubusercontent.com/alexgreensh/repo-forensics/HEAD/plugins/repo-forensics/skills/repo-forensics/SKILL.md What I want: (describe your task here)
If Claude can't open the link, open it yourself and paste the contents instead.
↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.
Install in the Claude app (no terminal)
- Download the ZIP with the button below.
- In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
- Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
Install in Claude Code
Let Claude do it — paste this into Claude Code
Install the skill I found on Claude Skill Mart. Copy the plugins/repo-forensics/skills/repo-forensics folder from the GitHub repo alexgreensh/repo-forensics into my ~/.claude/skills/repo-forensics/. When it's done, tell me in one line what this skill can do.
Install with a command instead
git clone https://github.com/alexgreensh/repo-forensics.git && mkdir -p ~/.claude/skills && cp -r repo-forensics/plugins/repo-forensics/skills/repo-forensics ~/.claude/skills/⚠ This is a third-party skill. Check the source repository before installing.
- Open a terminal and go to a working directory.
- Clone the repository:
git clone https://github.com/alexgreensh/repo-forensics.git - Create the skills directory:
mkdir -p ~/.claude/skills - Copy the skill in:
cp -r repo-forensics/plugins/repo-forensics/skills/repo-forensics ~/.claude/skills/ - Verify Python 3 is available:
python3 --version(optional:pip install yara-pythonto enable the YARA scanner). - Make the scripts executable:
chmod +x ~/.claude/skills/repo-forensics/scripts/*.sh - Restart Claude Code, then ask something like "audit this repo for security issues", or run
./scripts/run_forensics.sh /path/to/repodirectly.
View source on GitHub ↗License: NOASSERTION