Skill Scanner
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
Open-source security forensics - analyze repositories, dependencies, and code for malicious patterns, supply chain risks, and vulnerabilities.
$ npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AlexAI-MCP/hermes-CCC oss-forensics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AlexAI-MCP/hermes-CCC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oss-forensics .claude/skills/oss-forensics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "oss-forensics" agent skill from https://github.com/AlexAI-MCP/hermes-CCC/tree/master/skills/oss-forensics into .claude/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AlexAI-MCP/hermes-CCC/tree/master/skills/oss-forensicsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AlexAI-MCP/hermes-CCC oss-forensics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexAI-MCP/hermes-CCC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/oss-forensics .agents/skills/oss-forensics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/AlexAI-MCP/hermes-CCC/tree/master/skills/oss-forensics into .agents/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AlexAI-MCP/hermes-CCC oss-forensics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexAI-MCP/hermes-CCC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/oss-forensics .cursor/skills/oss-forensics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "oss-forensics" agent skill from https://github.com/AlexAI-MCP/hermes-CCC/tree/master/skills/oss-forensics into .cursor/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AlexAI-MCP/hermes-CCC.git --path skills/oss-forensics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AlexAI-MCP/hermes-CCC oss-forensics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexAI-MCP/hermes-CCC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/oss-forensics .gemini/skills/oss-forensics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/AlexAI-MCP/hermes-CCC/tree/master/skills/oss-forensics into .gemini/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AlexAI-MCP/hermes-CCC oss-forensicsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AlexAI-MCP/hermes-CCC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/oss-forensics .github/skills/oss-forensics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/AlexAI-MCP/hermes-CCC/tree/master/skills/oss-forensics into .github/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AlexAI-MCP/hermes-CCC oss-forensics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexAI-MCP/hermes-CCC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/oss-forensics .opencode/skills/oss-forensics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/AlexAI-MCP/hermes-CCC/tree/master/skills/oss-forensics into .opencode/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
oss-forensicsOpen-source security forensics - analyze repositories, dependencies, and code for malicious patterns, supply chain risks, and vulnerabilities.
Oss Forensics is an agent skill from AlexAI-MCP/hermes-CCC. Open-source security forensics - analyze repositories, dependencies, and code for malicious patterns, supply chain risks, and vulnerabilities.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security. The repository describes itself as: Hermes Agent ported to Claude Code Channel — 46 native skills, no OAuth, no external process. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8107e89. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipnpmcargotrivygitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, npm and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Oss Forensics loads about 1.8k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 884 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from AlexAI-MCP/hermes-CCC at commit 8107e89, republished under its MIT licence (© AlexAI-MCP). 884 words, ~1,824 tokens.
.claude/skills/oss-forensics/SKILL.md (or your agent's skills folder).Python:
pip auditNode:
npm auditRust:
cargo auditPython:
pip-licensesRepository-level license detection:
licensee detect .Using Syft:
syft .
syft image:myappCycloneDX example:
cyclonedx-bomContainer image scanning:
grype image:myappFilesystem scanning:
trivy fs ./grype for image/package matching against vulnerability databases.trivy fs ./ for repository and local filesystem scanning.Look for:
eval()exec()These are not proof by themselves, but they deserve deeper inspection.
Check for suspicious edits and removed secrets:
git log --all -S 'password'The question is not only "is this code vulnerable" but also "could this release path be hijacked."
pip audit, npm audit, or cargo audit as appropriate.syft or cyclonedx-bom.grype or trivy.eval(), exec(), base64 blobs, and obfuscation.pip audit, npm audit, and cargo audit.pip-licenses and licensee for license visibility.syft or cyclonedx-bom.grype image:myapp and trivy fs ./.eval(), exec(), and base64 payload blobs.git log --all -S 'password'.© AlexAI-MCP, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/oss-forensics of AlexAI-MCP/hermes-CCC.
Open the folder on GitHubat commit 8107e89
Oss Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Oss Forensics this skillAlexAI-MCP/hermes-CCC | 135 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Kesekit Checkcdppcorp/KESE-KIT | 360 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Bom Auditcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
jdx/packslip
Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…
AlexAI-MCP/hermes-CCC
Review GitHub pull requests with a findings-first engineering mindset.
AlexAI-MCP/hermes-CCC
Run a disciplined GitHub pull request workflow from branch creation through merge.
AlexAI-MCP/hermes-CCC
Manage durable project memory for Claude Code. An agent skill from AlexAI-MCP/hermes-CCC.
AlexAI-MCP/hermes-CCC
Route Claude Code work by complexity, risk, and tool needs. An agent skill from AlexAI-MCP/hermes-CCC.
AlexAI-MCP/hermes-CCC
Create, improve, inventory, and audit Claude Code skills. An agent skill from AlexAI-MCP/hermes-CCC.
AlexAI-MCP/hermes-CCC
Capture Claude Code interaction trajectories in training-friendly formats.
Categories
Open-source security forensics - analyze repositories, dependencies, and code for malicious patterns, supply chain risks, and vulnerabilities. Oss Forensics is an agent skill from AlexAI-MCP/hermes-CCC. Open-source security forensics - analyze repositories, dependencies, and code for malicious patterns, supply chain risks, and vulnerabilities.
Oss Forensics fits situations like: tasks that involve Supply chain security.
Run `npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a claude-code`. Or copy the skill folder (skills/oss-forensics in AlexAI-MCP/hermes-CCC) into .claude/skills/oss-forensics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a codex`. Or copy the skill folder (skills/oss-forensics in AlexAI-MCP/hermes-CCC) into .agents/skills/oss-forensics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AlexAI-MCP/hermes-CCC --skill oss-forensics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oss-forensics, .gemini/skills/oss-forensics, .github/skills/oss-forensics and .opencode/skills/oss-forensics in your project.
Going by SKILL.md and its folder, Oss Forensics needs the command-line tools its instructions call (pip, npm, cargo, trivy and git).
SKILL.md contains no URLs. Its commands use pip, npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Oss Forensics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Oss Forensics: Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars), Eu Cra (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Kesekit Check (cdppcorp/KESE-KIT, 360 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AlexAI-MCP (a GitHub user) maintains it in AlexAI-MCP/hermes-CCC, which has 135 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on April 8, 2026.
Source: AlexAI-MCP/hermes-CCC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.