oss-forensics

Identify open-source supply-chain compromises across repositories using a multi-agent forensics workflow.

1|Updated Jan 31, 2026
One-click install
npx skills add https://github.com/Monjyu1101/AiDiy2026 --skill oss-forensics-monjyu1101
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: oss-forensics
Source: https://github.com/Monjyu1101/AiDiy2026/tree/main/backend_hermes/optional-skills/security/oss-forensics
Command: npx skills add https://github.com/Monjyu1101/AiDiy2026 --skill oss-forensics-monjyu1101

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Defenders need a disciplined, evidence-driven approach to identify, analyze, and report open-source supply-chain compromises across repositories, while avoiding drift and hallucination.

Core Features & Use Cases

  • Multi-phase, multi-agent investigation framework (phase 0 through 7) for evidence collection, hypothesis formation, validation, and reporting.
  • Supports data fusion from local git repositories, GitHub REST API, Wayback Machine archives, and GitHub Archive/Bigit data sources for a comprehensive timeline.
  • Enforces guardrails (evidence citations, redaction of secrets, chain-of-custody) and generates formal forensic reports and evidence registries.

Quick Start

Run the oss-forensics skill to initiate a guided OSS supply-chain investigation and generate a structured report.

Frequently Asked Questions about oss-forensics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate an open-source supply-chain compromise across repositories?

To investigate a supply-chain compromise, you need a multi-phase forensics workflow that collects data from Git, GitHub API, and Wayback Machine archives, validates hypotheses, and generates structured forensic reports with strict evidence governance.

What is the best way to collect digital evidence from GitHub and Wayback Machine for security forensics?

The best way to collect digital evidence for security forensics is using a multi-source data fusion approach that queries the GitHub REST API and Wayback Machine archives, enforcing chain-of-custody and secret redaction to build a comprehensive timeline.

How do I prevent hallucination and evidence drift during an OSS security investigation?

To prevent hallucination and drift during an OSS security investigation, apply a formal multi-agent workflow that enforces strict evidence citations, redacts secrets, and consolidates findings into a structured evidence registry before final reporting.

Can I use GitHub Archive data for open-source supply-chain timeline reconstruction?

Yes, you can reconstruct an open-source supply-chain timeline by fusing local git repository data with GitHub Archive and BigQuery data sources, creating a comprehensive timeline supported by formal evidence collection guardrails.

Does the OSS forensics workflow generate formal evidence registries for supply-chain attacks?

Yes, the OSS forensics workflow generates formal forensic reports and structured evidence registries for supply-chain attacks, ensuring all collected data follows chain-of-custody rules and outputs redacted, validated artifacts.