Claude Skill MartBrowse skillsQuick linesLearn by videoTerminal guideWhat is a Skill?
← Back to list

Repo Forensics

Deep security auditing for git repos, AI skills and MCP servers — 28 scanners covering prompt injection, credential theft, supply-chain IOCs, and actively exploited CVEs.

Security & ReviewIntermediate★ 185⑂ 29AI score 10/10Last updated: Sep 27, 2026

What it does

  • Runs 28 scanners (secrets, SAST, dependencies, AST, DAST, archives, bytecode, git forensics, devcontainer, infra…) against a repo, AI skill, or MCP server.
  • Detects AI-agent-specific attacks: prompt injection, invisible unicode smuggling, credential exfiltration, persistence, MCP tool poisoning and rug-pull enablers.
  • Enriches dependency findings with live OSV data and cross-references CISA KEV — anything actively exploited in the wild is escalated to CRITICAL.
  • Flags manifest drift (declared vs actually used deps) and runtime dynamism (time bombs, fetch-then-execute, self-modifying code).
  • Emits text/json/summary/sarif with deterministic exit codes (0/1/2/99) for CI gating.
  • Scope is stated up front: it does not fix vulnerabilities or run pentests, and skips .7z/.rar/encrypted archives plus Java/Node/wasm bytecode.

Who it's for

  • Anyone vetting third-party Claude Code skills, plugins, or MCP servers before installing them.
  • Developers and security engineers reviewing supply-chain risk in new dependencies.
  • Teams wiring an automated security gate into CI/CD.
  • Incident responders hunting compromise artifacts (RAT binaries, C2 persistence, npm cache traces).

Examples

  1. Pre-install skill vetting: ./scripts/run_forensics.sh ~/Downloads/some-skill --skill-scan runs the faster 18-scanner pass to surface hidden SKILL.md directives or curl-pipe-bash prerequisites.
  2. CI gate: ./scripts/run_forensics.sh . --format json, parse the report and fail the build on CRITICAL (exit code 2).
  3. Incident investigation: ./scripts/run_forensics.sh /path/to/repo --update-iocs --watch pulls fresh IOCs, matches C2 domains and malicious hashes, and alerts on config-file drift.

· · · Install guide · · ·

Try it now, no install

Paste this into Claude to use the skill without installing anything.

Read the instructions in this file and follow them to help me:
https://raw.githubusercontent.com/alexgreensh/repo-forensics/HEAD/plugins/repo-forensics/skills/repo-forensics/SKILL.md

What I want: (describe your task here)

If Claude can't open the link, open it yourself and paste the contents instead.

↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.

Install in the Claude app (no terminal)
  1. Download the ZIP with the button below.
  2. In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
  3. Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
↓ Download ZIP
Install in Claude Code

Let Claude do it — paste this into Claude Code

Install the skill I found on Claude Skill Mart.
Copy the plugins/repo-forensics/skills/repo-forensics folder from the GitHub repo alexgreensh/repo-forensics into my ~/.claude/skills/repo-forensics/.
When it's done, tell me in one line what this skill can do.

Install with a command instead

git clone https://github.com/alexgreensh/repo-forensics.git && mkdir -p ~/.claude/skills && cp -r repo-forensics/plugins/repo-forensics/skills/repo-forensics ~/.claude/skills/

⚠ This is a third-party skill. Check the source repository before installing.

  1. Open a terminal and go to a working directory.
  2. Clone the repository: git clone https://github.com/alexgreensh/repo-forensics.git
  3. Create the skills directory: mkdir -p ~/.claude/skills
  4. Copy the skill in: cp -r repo-forensics/plugins/repo-forensics/skills/repo-forensics ~/.claude/skills/
  5. Verify Python 3 is available: python3 --version (optional: pip install yara-python to enable the YARA scanner).
  6. Make the scripts executable: chmod +x ~/.claude/skills/repo-forensics/scripts/*.sh
  7. Restart Claude Code, then ask something like "audit this repo for security issues", or run ./scripts/run_forensics.sh /path/to/repo directly.
View source on GitHub ↗License: NOASSERTION