Favicon of oss-forensics

oss-forensics Skill

AI Agent SkillPythonOpen source

GitHub supply-chain forensics: recovery, IOCs, reporting. Published by NousResearch in hermes-agent.

Decision snapshot

Is this a fit?

Best for

Security review, Data analysis, Includes SKILL.md, Reusable instructions

Works with

Compatibility not yet detected.

Access

Permission behavior not yet detected.

Setup

Copy skill directory

Project health

21 days ago · MIT license

Considerations

No specific cautions were detected. Review the source and requested permissions before installing.

What is oss-forensics Skill?

GitHub supply-chain forensics: recovery, IOCs, reporting. Published by NousResearch in hermes-agent. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
100/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Security review
  • Data analysis
  • Security review use cases
  • Data analysis use cases

Declared skill metadata

  • Declared author: Teknium (teknium1), Hermes Agent
  • Declared license: MIT
  • Source file: optional-skills/security/oss-forensics/SKILL.md

These fields retain source and confidence evidence from the indexed SKILL.md.

Compatibility and setup

Copy skill directory
  • Install or run with Copy skill directory

When to use oss-forensics Skill

  • Use it for security review.
  • Use it for data analysis.

Built with

PythonCopy skill directory

Editorial notes

Source

  • Creator: NousResearch
  • Repository: NousResearch/hermes-agent
  • Skill file: optional-skills/security/oss-forensics/SKILL.md

What it does

GitHub supply-chain forensics: recovery, IOCs, reporting.

Skill instructions

OSS Security Forensics Skill A 7-phase multi-agent investigation framework for researching open-source supply chain attacks. Adapted from RAPTOR's forensics system. Covers GitHub Archive, Wayback Machine, GitHub API, local git analysis, IOC extraction, evidence-backed hypothesis formation and validation, and final forensic report generation. --- ⚠️ Anti-Hallucination Guardrails Read these before every investigation step. Violating them invalidates the report. 1. Evidence-First Rule: Every claim in any report, hypothesis, or summary MUST cite at least one evidence ID (EV-XXXX). Assertions without citations are forbidden. 2. STAY IN YOUR LANE: Each sub-agent (investigator) has a single data source. Do NOT mix sources. The GH Archive investigator does not query the GitHub API, and vice versa. Role boundaries are hard. 3. Fact vs. Hypothesis Separation: Mark all unverified inferences with [HYPOTHESIS]. Only statements verified against original sources may be stated as facts. 4. No Evidence

Verified compatibility and discovery

Frequently asked questions

What is oss-forensics?

oss-forensics is a open-source AI agent skill with Copy skill directory. GitHub supply-chain forensics: recovery, IOCs, reporting.

Who is oss-forensics best for?

oss-forensics is best for reusing agent instructions, scripts, and references, security review workflows, data analysis workflows.

How do I install oss-forensics?

Install or run oss-forensics using Copy skill directory. Check oss-forensics for the latest setup command.

Is oss-forensics actively maintained?

oss-forensics may need a closer maintenance check before production use.

Share:

Stars
232,138
Forks
46,253
Last commit
21 days ago
Last verified
Aug 18, 2026
Metadata fetched
Aug 18, 2026
Repository age
1 year
License
MIT

Project health auto-fetched from the source repository.

Maintain this resource?

Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.

Alternatives to oss-forensics