oss-forensics

Recover deleted commits and analyze GitHub security anomalies for supply chain investigations.

Updated Jun 25, 2026
One-click install
npx skills add https://github.com/davpatel605-beep/hermusagent --skill oss-forensics-davpatel605-beep
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: oss-forensics
Source: https://github.com/davpatel605-beep/hermusagent/tree/main/backend/vendor/hermes/optional-skills/security/oss-forensics
Command: npx skills add https://github.com/davpatel605-beep/hermusagent --skill oss-forensics-davpatel605-beep

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps security teams investigate suspected open-source supply chain compromises by collecting, validating, and organizing forensic evidence instead of relying on unverified assumptions.

Core Features & Use Cases

  • Repository Forensics: Analyze Git history, GitHub activity, archived content, and external records to recover deleted commits, detect force pushes, and reconstruct timelines.
  • Evidence-Based Investigation: Manage indicators of compromise, enforce evidence citations, validate hypotheses, and generate structured forensic reports.
  • Use Case: Investigate a suspicious repository after a suspected maintainer takeover by correlating commit history, GitHub events, archived snapshots, and IOC data into a defensible security report.

Quick Start

Use the oss-forensics skill to investigate this repository for possible supply chain compromise and produce an evidence-backed forensic report.

Frequently Asked Questions about oss-forensics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate a suspected open-source supply chain compromise on GitHub?

To investigate an open-source supply chain compromise, collect repository evidence by recovering deleted commits, detecting force pushes, and correlating GitHub activity to generate a structured forensic report.

Can I recover deleted commits and detect force pushes during a repository investigation?

Yes, repository forensics can recover deleted commits and detect force pushes by analyzing Git history, GitHub activity logs, and archived content to reconstruct a timeline of unauthorized repository modifications.

How do I extract indicators of compromise and validate evidence during a security investigation?

Extract indicators of compromise and validate evidence by applying multi-source validation, enforcing evidence citations, and structuring findings into a defensible forensic report.

What is the best way to investigate a maintainer takeover in an open-source repository?

The best way to investigate a maintainer takeover is to correlate commit history, GitHub events, and archived snapshots with IOC data to validate hypotheses and produce an evidence-backed forensic report.

Do I need external archived records to validate GitHub supply chain security anomalies?

Yes, multi-source validation requires external records like archived snapshots and GitHub event logs to reconstruct timelines and validate security anomalies during a supply chain compromise investigation.

When should I use forensic evidence tracking for a GitHub repository security analysis?

Use forensic evidence tracking when investigating suspected supply chain compromises that require recovering deleted commits, extracting IOCs, and generating structured reports with defensible evidence citations.