What problem does it solve?
This Skill helps you investigate whether a GitHub repository has been compromised, tampered with, or rewritten to hide suspicious activity, while keeping every conclusion anchored to evidence.
Core Features & Use Cases
- Repository Forensics: Reconstruct commit history, detect force-pushes, and identify dangling or deleted changes in local git data.
- Multi-Source Correlation: Cross-check GitHub API data, GitHub Archive events, and Wayback snapshots to spot deletions, rewrites, and permission changes.
- IOC Handling and Reporting: Extract indicators of compromise, enrich them from passive public sources, validate hypotheses, and generate a structured forensic report.
- Use Case: Investigate a suspicious open-source repository after a maintainer account anomaly, recover erased commits, and produce an evidence-backed timeline for responders.
Quick Start
Ask this Skill to investigate a GitHub repository for compromise indicators, recover deleted history, and produce an evidence-backed forensic report.