oss-forensics

Coordinate multi-agent investigations of OSS supply-chain compromises across git, GitHub API, Wayback Machine, and GH Archive.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/AlexKoncept/omnia-hub --skill oss-forensics-alexkoncept
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: oss-forensics
Source: https://github.com/AlexKoncept/omnia-hub/tree/main/HERMES/optional-skills/security/oss-forensics
Command: npx skills add https://github.com/AlexKoncept/omnia-hub --skill oss-forensics-alexkoncept

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Supply chain investigations for open-source repositories are complex and error-prone; this skill provides a structured, multi-agent framework to gather, correlate, and validate evidence across multiple sources (local git data, GitHub REST API, Wayback Machine, and GH Archive) and generate a comprehensive forensic report.

Core Features & Use Cases

  • Phase-driven investigation framework (initialization, evidence collection, hypothesis formation, validation, and final reporting) to ensure repeatable workflows.
  • Multi-source evidence integration (local git data, GitHub API, web archives, and GH Archive) for cross-source verification and robust conclusions.
  • Automated artifact generation (evidence registry, timeline, validated hypotheses, and a final investigation report) suitable for disclosure and remediation.

Quick Start

Initiate Phase 0 for your target repository and follow Phase 3 through Phase 6 to produce the final forensic report.

Frequently Asked Questions about oss-forensics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate an open-source supply-chain compromise?

Supply-chain forensics investigates OSS compromises by collecting multi-source evidence across local git data, GitHub APIs, Wayback Machine, and GH Archive. This framework coordinates a multi-agent investigation to build a timeline, test hypotheses, and produce a structured final report with an evidence registry and mitigations.

What is the best way to collect evidence from a compromised GitHub repository?

Collecting evidence from a compromised GitHub repository requires multi-source integration across local git data, the GitHub REST API, Wayback Machine snapshots, and GH Archive. This approach cross-verifies findings to build a robust timeline and generate an evidence registry suitable for disclosure.

How do I verify hypotheses during a software supply-chain investigation?

Verify hypotheses during a software supply-chain investigation by cross-referencing multi-source evidence from local git data, GitHub APIs, and web archives. This framework forms and validates hypotheses against an integrated timeline to ensure robust conclusions before generating a final forensic report.

Can I use git forensics to generate a report suitable for vulnerability disclosure?

Yes, you can use git forensics to generate a report suitable for vulnerability disclosure. This framework produces automated artifacts including an evidence registry, validated hypotheses, a timeline, and a final investigation report with mitigations specifically structured for disclosure and remediation.

Does supply-chain forensics work with Wayback Machine and GH Archive data?

Yes, supply-chain forensics integrates Wayback Machine and GH Archive data alongside local git data and the GitHub API. This multi-source evidence collection ensures cross-source verification, allowing you to build a robust timeline and validate hypotheses for your final forensic report.