oss-forensics - Investigate GitHub repositories for supply chain threats
Collects and analyzes Git, GitHub, web archive, and other evidence to investigate repository compromise and produce a forensic report.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Parse investigation targets
- Extract indicators of compromise
- Collect local Git evidence
- Query GitHub repository data
- Search Wayback snapshots
- Recover deleted commits
- Detect rewritten history
- Form evidence-backed hypotheses
- Validate forensic hypotheses
- Generate forensic reports
Inputs
- Target GitHub repository
- Investigation goal
- Investigation time window
- Target actors
- Provided indicators of compromise
- Linked security reports
- Local Git repository
Outputs
- Evidence store
- IOC tracking file
- Collected evidence files
- Investigation report
- Validated forensic hypotheses
Requirements
- Terminal access
- Web access
- File access
- Delegation support
- Python 3
- Git
- curl
