What problem does it solve?
This Skill provides a comprehensive framework for investigating GitHub repositories, uncovering potential security breaches, and responding to supply chain attacks.
Core Features & Use Cases
- Supply Chain Attack Investigation: Investigate potential breaches and analyze deleted commits, force-pushes, and compromised dependencies.
- Evidence Collection: Collect and verify evidence from local git repositories, GitHub API, GitHub Archive, and Wayback Machine.
- Hypothesis Formation & Validation: Formulate and validate hypotheses using a structured approach, ensuring evidence is cross-referenced and logically consistent.
- Structured Reporting: Generate detailed forensic reports with evidence registry, Indicators of Compromise, and recommendations.
- Use Case: When a suspicious commit is found in a repository, use this Skill to perform a thorough investigation, collect evidence, and validate or refute the hypothesis.
Quick Start
Use the oss-forensics skill to investigate the repository 'OWNER/REPO'.