What problem does it solve?
This Skill helps investigate open-source repositories for supply chain compromise, deleted history, suspicious collaborator activity, and other signs of tampering while keeping findings evidence-backed.
Core Features & Use Cases
- Multi-source investigation: Correlates local git data, GitHub API responses, Wayback Machine snapshots, and GitHub Archive events.
- History recovery: Finds force-pushes, dangling commits, deleted branches, and missing pull requests or issues.
- IOC extraction and enrichment: Captures commit SHAs, file paths, accounts, domains, packages, and secrets for follow-up analysis.
- Structured forensic reporting: Produces a timeline, validated hypotheses, evidence registry, and mitigation recommendations.
- Use case: Analyze a suspicious repository after a reported compromise and reconstruct what changed, when it changed, and who likely made the change.
Quick Start
Ask the skill to investigate a specific GitHub repository for supply chain compromise and produce an evidence-backed forensic report.