What problem does it solve?
This Skill solves the complex, time-sensitive problem of investigating suspected open source software supply chain attacks, where critical evidence may be deleted, hidden via force-pushes, or scattered across multiple archival and API sources.
Core Features & Use Cases
- 7-Phase Multi-Agent Investigation Framework: Orchestrates specialized sub-agents to collect, cross-reference, and validate evidence without mixing data sources, ensuring investigation integrity.
- Multi-Source Evidence Recovery: Pulls data from local git repositories, GitHub REST API, Wayback Machine archives, and GitHub Archive BigQuery to recover deleted commits, issues, PRs, and hidden repository changes.
- Structured Forensic Reporting: Generates evidence-backed, citation-mandated reports with validated hypotheses, full IOC lists, and chain of custody for responsible vulnerability disclosure.
- Use Case: If you suspect a critical open source library was compromised via a malicious maintainer commit, use this Skill to recover force-pushed evidence, validate attack hypotheses, and produce a report for coordinated disclosure with maintainers and package registries.
Quick Start
Use the oss-forensics skill to investigate the repository owner/repo for signs of supply chain compromise, recover any deleted commit evidence, and generate a full forensic report with validated findings.