oss-forensics Skill
Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Covers deleted commit recovery, force-push detection, IOC extraction, multi-source evidence collection, hypothesis formation/validation, and structured forensic reporting. Inspired by RAPTOR's 1800+ line OSS Forensics system. Published by NousResearch in hermes-agent.
What is oss-forensics Skill?
Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Covers deleted commit recovery, force-push detection, IOC extraction, multi-source evidence collection, hypothesis formation/validation, and structured forensic reporting. Inspired by RAPTOR's 1800+ line OSS Forensics system. Published by NousResearch in hermes-agent. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Data analysis
- Security review use cases
- Data analysis use cases
Technical details
- Install or run with Copy skill directory
When to use oss-forensics Skill
- Use it for security review.
- Use it for data analysis.
Built with
Editorial notes
Source
- Creator: NousResearch
- Repository: NousResearch/hermes-agent
- Skill file: optional-skills/security/oss-forensics/SKILL.md
What it does
Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Covers deleted commit recovery, force-push detection, IOC extraction, multi-source evidence collection, hypothesis formation/validation, and structured forensic reporting. Inspired by RAPTOR's 1800+ line OSS Forensics system.
Skill instructions
OSS Security Forensics Skill A 7-phase multi-agent investigation framework for researching open-source supply chain attacks. Adapted from RAPTOR's forensics system. Covers GitHub Archive, Wayback Machine, GitHub API, local git analysis, IOC extraction, evidence-backed hypothesis formation and validation, and final forensic report generation. --- ⚠️ Anti-Hallucination Guardrails Read these before every investigation step. Violating them invalidates the report. 1. Evidence-First Rule: Every claim in any report, hypothesis, or summary MUST cite at least one evidence ID (EV-XXXX). Assertions without citations are forbidden. 2. STAY IN YOUR LANE: Each sub-agent (investigator) has a single data source. Do NOT mix sources. The GH Archive investigator does not query the GitHub API, and vice versa. Role boundaries are hard. 3. Fact vs. Hypothesis Separation: Mark all unverified inferences with [HYPOTHESIS]. Only statements verified against original sources may be stated as facts. 4. No Evidence
Explore related resources
Frequently asked questions
What is oss-forensics?
oss-forensics is a open-source AI agent skill with Copy skill directory. Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.
Who is oss-forensics best for?
oss-forensics is best for reusing agent instructions, scripts, and references, security review workflows, data analysis workflows.
How do I install oss-forensics?
Install or run oss-forensics using Copy skill directory. Check oss-forensics for the latest setup command.
Is oss-forensics actively maintained?
oss-forensics may need a closer maintenance check before production use.
Auto-fetched from GitHub.