What problem does it solve?
Open-source software ecosystems are frequently targeted by supply-chain attacks and stealth compromises. This Skill provides a rigorous, multi-source forensic framework to collect, correlate, and reason about evidence across Git history, GitHub events, archival records, and IOC enrichment to determine if a repository has been compromised and to produce defensible remediation guidance.
Core Features & Use Cases
- Multi-source evidence gathering across local git data, GitHub REST API responses, GitHub Archive (BigQuery), and Wayback Machine snapshots.
- Phase-driven investigation workflow including initialization, evidence collection, hypothesis formation, validation, and final reporting.
- Structured evidence registry with citations, cross-source correlations, and a final forensic report suitable for disclosure and remediation planning.
- Use Case: Investigate a suspected supply-chain attack in an OSS repository and generate a timeline, validated hypotheses, and actionable mitigations.
Quick Start
Run an OSS forensics investigation against a target repository to begin collecting structured evidence and generate an investigative report.