oss-forensics - Investigate GitHub supply-chain incidents
Investigates GitHub supply-chain incidents by collecting and validating repository evidence, recovering deleted history, extracting IOCs, and generating forensic reports.
Tags
Updated: 2026-10-08Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Parse investigation targets
- Extract threat indicators
- Collect local Git evidence
- Query GitHub REST API
- Search Wayback snapshots
- Query GH Archive events
- Enrich IOC information
- Validate evidence hashes
- Classify timeline evidence
- Form evidence-based hypotheses
- Verify hypothesis evidence
- Generate forensic reports
Inputs
- Target repository
- Investigation objectives
- Investigation time range
- Known threat indicators
- Related security reports
- Local Git repository
- Public passive data
- Google Cloud credentials
Outputs
- investigation directory
- evidence.json
- investigation-report.md
- iocs.md
- Collected evidence files
- Validated evidence statuses
- Forensic findings
Requirements
- Terminal access
- Web access
- File access
- Task delegation support
- Linux, macOS, or Windows
- Google Cloud BigQuery access for GH Archive queries
