Supply Chain Security
zhaoxuya520/reverse-skill
A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.
$ npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Tommy-yw/RunbookHermes oss-forensics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Tommy-yw/RunbookHermes.git skills-src && mkdir -p .claude/skills && cp -r skills-src/optional-skills/security/oss-forensics .claude/skills/oss-forensics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "oss-forensics" agent skill from https://github.com/Tommy-yw/RunbookHermes/tree/main/optional-skills/security/oss-forensics into .claude/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Tommy-yw/RunbookHermes/tree/main/optional-skills/security/oss-forensicsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Tommy-yw/RunbookHermes oss-forensics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tommy-yw/RunbookHermes.git skills-src && mkdir -p .agents/skills && cp -r skills-src/optional-skills/security/oss-forensics .agents/skills/oss-forensics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/Tommy-yw/RunbookHermes/tree/main/optional-skills/security/oss-forensics into .agents/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Tommy-yw/RunbookHermes oss-forensics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tommy-yw/RunbookHermes.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/optional-skills/security/oss-forensics .cursor/skills/oss-forensics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "oss-forensics" agent skill from https://github.com/Tommy-yw/RunbookHermes/tree/main/optional-skills/security/oss-forensics into .cursor/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Tommy-yw/RunbookHermes.git --path optional-skills/security/oss-forensics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Tommy-yw/RunbookHermes oss-forensics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tommy-yw/RunbookHermes.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/optional-skills/security/oss-forensics .gemini/skills/oss-forensics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/Tommy-yw/RunbookHermes/tree/main/optional-skills/security/oss-forensics into .gemini/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Tommy-yw/RunbookHermes oss-forensicsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Tommy-yw/RunbookHermes.git skills-src && mkdir -p .github/skills && cp -r skills-src/optional-skills/security/oss-forensics .github/skills/oss-forensics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/Tommy-yw/RunbookHermes/tree/main/optional-skills/security/oss-forensics into .github/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Tommy-yw/RunbookHermes oss-forensics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tommy-yw/RunbookHermes.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/optional-skills/security/oss-forensics .opencode/skills/oss-forensics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "oss-forensics" agent skill from https://github.com/Tommy-yw/RunbookHermes/tree/main/optional-skills/security/oss-forensics into .opencode/skills/oss-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-forensics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
oss-forensicsSupply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.
Oss Forensics is an agent skill from Tommy-yw/RunbookHermes. Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Covers deleted commit recovery, force-push detection, IOC extraction, multi-source evidence collection, hypothesis formation/validation, and structured forensic reporting. Inspired by RAPTOR's 1800+ line OSS Forensics system.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/evidence-types.md`, `references/github-archive-guide.md` and `references/investigation-templates.md`).
It sits in Security, covering Digital forensics and Supply chain security. It works with GitHub. The repository describes itself as: Hermes-native AIOps agent for evidence-driven incident response, approval-gated remediation, and runbook learning. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7fd2b9a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
curlgitpython3bqjqgcloudFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.github.comweb.archive.orggithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENAPI_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Oss Forensics loads about 5k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 1,858 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from Tommy-yw/RunbookHermes at commit 7fd2b9a, republished under its MIT licence (© Tommy-yw). 1,858 words, ~4,969 tokens.
.claude/skills/oss-forensics/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.A 7-phase multi-agent investigation framework for researching open-source supply chain attacks. Adapted from RAPTOR's forensics system. Covers GitHub Archive, Wayback Machine, GitHub API, local git analysis, IOC extraction, evidence-backed hypothesis formation and validation, and final forensic report generation.
Read these before every investigation step. Violating them invalidates the report.
EV-XXXX). Assertions without citations are forbidden.[HYPOTHESIS]. Only statements verified against original sources may be stated as facts.execute_code in a sandboxed environment.internal-lib-v2 is uploaded to NPM with a higher version than the internal one. The investigator must track when this package was first seen and if any PushEvents in the target repo updated package.json to this version..github/workflows/build.yml. The investigator looks for PushEvents from this user after a long period of inactivity or from a new IP/location (if detectable via BigQuery).git fsck and GH Archive to recover the original commit SHA and verify what was leaked.Path convention: Throughout this skill,
SKILL_DIRrefers to the root of this skill's installation directory (the folder containing thisSKILL.md). When the skill is loaded, resolveSKILL_DIRto the actual path — e.g.~/.hermes/skills/security/oss-forensics/or theoptional-skills/equivalent. All script and template references are relative to it.
mkdir investigation_$(echo "REPO_NAME" | tr '/' '_')
cd investigation_$(echo "REPO_NAME" | tr '/' '_')python3 SKILL_DIR/scripts/evidence-store.py --store evidence.json listcp SKILL_DIR/templates/forensic-report.md ./investigation-report.mdiocs.md file to track Indicators of Compromise as they are discovered.Goal: Extract all structured investigative targets from the user's request.
Actions:
owner/repo)Tools: Reasoning only, or execute_code for regex extraction from large text blocks.
Output: Populate iocs.md with extracted IOCs. Each IOC must have:
Reference: See evidence-types.md for IOC taxonomy.
Spawn up to 5 specialist investigator sub-agents using delegate_task (batch mode, max 3 concurrent). Each investigator has a single data source and must not mix sources.
Orchestrator note: Pass the IOC list from Phase 1 and the investigation time window in the
contextfield of each delegated task.
ROLE BOUNDARY: You query the LOCAL GIT REPOSITORY ONLY. Do not call any external APIs.
Actions:
# Clone repository
git clone https://github.com/OWNER/REPO.git target_repo && cd target_repo
# Full commit log with stats
git log --all --full-history --stat --format="%H|%ae|%an|%ai|%s" > ../git_log.txt
# Detect force-push evidence (orphaned/dangling commits)
git fsck --lost-found --unreachable 2>&1 | grep commit > ../dangling_commits.txt
# Check reflog for rewritten history
git reflog --all > ../reflog.txt
# List ALL branches including deleted remote refs
git branch -a -v > ../branches.txt
# Find suspicious large binary additions
git log --all --diff-filter=A --name-only --format="%H %ai" -- "*.so" "*.dll" "*.exe" "*.bin" > ../binary_additions.txt
# Check for GPG signature anomalies
git log --show-signature --format="%H %ai %aN" > ../signature_check.txt 2>&1Evidence to collect (add via python3 SKILL_DIR/scripts/evidence-store.py add):
gitgitgitgitReference: See recovery-techniques.md for accessing force-pushed commits.
ROLE BOUNDARY: You query the GITHUB REST API ONLY. Do not run git commands locally.
Actions:
# Commits (paginated)
curl -s "https://api.github.com/repos/OWNER/REPO/commits?per_page=100" > api_commits.json
# Pull Requests including closed/deleted
curl -s "https://api.github.com/repos/OWNER/REPO/pulls?state=all&per_page=100" > api_prs.json
# Issues
curl -s "https://api.github.com/repos/OWNER/REPO/issues?state=all&per_page=100" > api_issues.json
# Contributors and collaborator changes
curl -s "https://api.github.com/repos/OWNER/REPO/contributors" > api_contributors.json
# Repository events (last 300)
curl -s "https://api.github.com/repos/OWNER/REPO/events?per_page=100" > api_events.json
# Check specific suspicious commit SHA details
curl -s "https://api.github.com/repos/OWNER/REPO/git/commits/SHA" > commit_detail.json
# Releases
curl -s "https://api.github.com/repos/OWNER/REPO/releases?per_page=100" > api_releases.json
# Check if a specific commit exists (force-pushed commits may 404 on commits/ but succeed on git/commits/)
curl -s "https://api.github.com/repos/OWNER/REPO/commits/SHA" | jq .shaCross-reference targets (flag discrepancies as evidence):
Reference: See evidence-types.md for GH event types.
ROLE BOUNDARY: You query the WAYBACK MACHINE CDX API ONLY. Do not use the GitHub API.
Goal: Recover deleted GitHub pages (READMEs, issues, PRs, releases, wiki pages).
Actions:
# Search for archived snapshots of the repo main page
curl -s "https://web.archive.org/cdx/search/cdx?url=github.com/OWNER/REPO&output=json&limit=100&from=YYYYMMDD&to=YYYYMMDD" > wayback_main.json
# Search for a specific deleted issue
curl -s "https://web.archive.org/cdx/search/cdx?url=github.com/OWNER/REPO/issues/NUM&output=json&limit=50" > wayback_issue_NUM.json
# Search for a specific deleted PR
curl -s "https://web.archive.org/cdx/search/cdx?url=github.com/OWNER/REPO/pull/NUM&output=json&limit=50" > wayback_pr_NUM.json
# Fetch the best snapshot of a page
# Use the Wayback Machine URL: https://web.archive.org/web/TIMESTAMP/ORIGINAL_URL
# Example: https://web.archive.org/web/20240101000000*/github.com/OWNER/REPO
# Advanced: Search for deleted releases/tags
curl -s "https://web.archive.org/cdx/search/cdx?url=github.com/OWNER/REPO/releases/tag/*&output=json" > wayback_tags.json
# Advanced: Search for historical wiki changes
curl -s "https://web.archive.org/cdx/search/cdx?url=github.com/OWNER/REPO/wiki/*&output=json" > wayback_wiki.jsonEvidence to collect:
Reference: See github-archive-guide.md for CDX API parameters.
ROLE BOUNDARY: You query GITHUB ARCHIVE via BIGQUERY ONLY. This is a tamper-proof record of all public GitHub events.
Prerequisites: Requires Google Cloud credentials with BigQuery access (
gcloud auth application-default login). If unavailable, skip this investigator and note it in the report.
Cost Optimization Rules (MANDATORY):
--dry_run before every query to estimate cost._TABLE_SUFFIX to filter by date range and minimize scanned data.# Template: safe BigQuery query for PushEvents to OWNER/REPO
bq query --use_legacy_sql=false --dry_run "
SELECT created_at, actor.login, payload.commits, payload.before, payload.head,
payload.size, payload.distinct_size
FROM \`githubarchive.month.*\`
WHERE _TABLE_SUFFIX BETWEEN 'YYYYMM' AND 'YYYYMM'
AND type = 'PushEvent'
AND repo.name = 'OWNER/REPO'
LIMIT 1000
"
# If cost is acceptable, re-run without --dry_run
# Detect force-pushes: zero-distinct_size PushEvents mean commits were force-erased
# payload.distinct_size = 0 AND payload.size > 0 → force push indicator
# Check for deleted branch events
bq query --use_legacy_sql=false "
SELECT created_at, actor.login, payload.ref, payload.ref_type
FROM \`githubarchive.month.*\`
WHERE _TABLE_SUFFIX BETWEEN 'YYYYMM' AND 'YYYYMM'
AND type = 'DeleteEvent'
AND repo.name = 'OWNER/REPO'
LIMIT 200
"Evidence to collect:
Reference: See github-archive-guide.md for all 12 event types and query patterns.
ROLE BOUNDARY: You enrich EXISTING IOCs from Phase 1 using passive public sources ONLY. Do not execute any code from the target repository.
Actions:
github.com/OWNER/REPO/commit/SHA.patch)web_extract on public WHOIS services)After all investigators complete:
python3 SKILL_DIR/scripts/evidence-store.py --store evidence.json list to see all collected evidence.content_sha256 hash matches the original source.[VERIFIED] (confirmed from 2+ independent sources) or [UNVERIFIED] (single source only).A hypothesis must:
EV-XXXX, EV-YYYY)[HYPOTHESIS] until validatedCommon hypothesis templates (see investigation-templates.md):
For each hypothesis, spawn a delegate_task sub-agent to attempt to find disconfirming evidence before confirming.
The validator sub-agent MUST mechanically check:
evidence.json (hard failure if any ID is missing → hypothesis rejected as potentially fabricated).[VERIFIED] piece of evidence was confirmed from 2+ sources.Output:
VALIDATED: All evidence cited, verified, logically consistent, no plausible alternative explanation.INCONCLUSIVE: Evidence supports hypothesis but alternative explanations exist or evidence is insufficient.REJECTED: Missing evidence IDs, unverified evidence cited as fact, logical inconsistency detected.Rejected hypotheses feed back into Phase 4 for refinement (max 3 iterations).
Populate investigation-report.md using the template in forensic-report.md.
Mandatory sections:
EV-XXXX entries with source, type, and verification statusReport rules:
[EV-XXXX] citation[REDACTED]python3 SKILL_DIR/scripts/evidence-store.py --store evidence.json listinvestigation-report.md to the user.This skill is designed for defensive security investigation — protecting open-source software from supply chain attacks. It must not be used for:
Investigations should be conducted with the principle of minimal intrusion: collect only the evidence necessary to validate or refute the hypothesis. When publishing results, follow responsible disclosure practices and coordinate with affected maintainers before public disclosure.
If the investigation reveals a genuine compromise, follow the coordinated vulnerability disclosure process:
GitHub REST API enforces rate limits that will interrupt large investigations if not managed.
Authenticated requests: 5,000/hour (requires GITHUB_TOKEN env var or gh CLI auth)
Unauthenticated requests: 60/hour (unusable for investigations)
Best practices:
export GITHUB_TOKEN=ghp_... or use gh CLI (auto-authenticates)If-None-Match / If-Modified-Since headers) to avoid consuming quota on unchanged dataX-RateLimit-Remaining header; if below 100, pause for X-RateLimit-Reset timestampIf rate-limited mid-investigation, record the partial results in the evidence store and note the limitation in the report.
© Tommy-yw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in optional-skills/security/oss-forensics of Tommy-yw/RunbookHermes.
Open the folder on GitHubat commit 7fd2b9a
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in Tommy-yw/RunbookHermes, which our catalogue first saw on October 7, 2026.
Oss Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Oss Forensics this skillTommy-yw/RunbookHermes | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | |
| Supply Chain Securityzhaoxuya520/reverse-skill | 40k | 4 repos | ~953 | Automated safety check: Warn | MIT | |
| Docsboostsecurityio/poutine | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | |
| Snapshotboostsecurityio/poutine | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | |
| Update Vulndbboostsecurityio/poutine | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 | |
| PR Auditakitaonrails/my-skills | 212 | — | ~4.8k | Automated safety check: Pass | None |
zhaoxuya520/reverse-skill
A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
boostsecurityio/poutine
Update project documentation when features are added or changed.
boostsecurityio/poutine
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
boostsecurityio/poutine
Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.
akitaonrails/my-skills
Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation…
github/gh-aw
Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration.
Tommy-yw/RunbookHermes
Build, test, inspect, install, and deploy MCP servers with FastMCP in Python.
Tommy-yw/RunbookHermes
Pharmaceutical research assistant for drug discovery workflows.
Tommy-yw/RunbookHermes
Fetch YouTube video transcripts and transform them into structured content (chapters, summaries, threads, blog posts).
Tommy-yw/RunbookHermes
Production pipeline for interactive and generative visual art using p5.js.
Tommy-yw/RunbookHermes
Set up and use 1Password CLI (op). An agent skill from Tommy-yw/RunbookHermes.
Tommy-yw/RunbookHermes
Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for Hermes.
Works with
Categories
Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Oss Forensics is an agent skill from Tommy-yw/RunbookHermes. Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.
Oss Forensics fits situations like: tasks that involve Digital forensics; tasks that involve Supply chain security.
Run `npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a claude-code`. Or copy the skill folder (optional-skills/security/oss-forensics in Tommy-yw/RunbookHermes) into .claude/skills/oss-forensics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a codex`. Or copy the skill folder (optional-skills/security/oss-forensics in Tommy-yw/RunbookHermes) into .agents/skills/oss-forensics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Tommy-yw/RunbookHermes --skill oss-forensics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oss-forensics, .gemini/skills/oss-forensics, .github/skills/oss-forensics and .opencode/skills/oss-forensics in your project.
Going by SKILL.md and its folder, Oss Forensics needs Python for the scripts in its folder, the command-line tools its instructions call (curl, git, python3, bq, jq and gcloud) and credentials named GITHUB_TOKEN and API_KEY. Our summary lists: Python 3; A credential in API_KEY.
SKILL.md names 3 domains. In commands or code: api.github.com, web.archive.org and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Oss Forensics is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Oss Forensics: Supply Chain Security (zhaoxuya520/reverse-skill, 40k stars), Docs (boostsecurityio/poutine, 523 stars), Snapshot (boostsecurityio/poutine, 523 stars) and Update Vulndb (boostsecurityio/poutine, 523 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Tommy-yw (a GitHub user) maintains it in Tommy-yw/RunbookHermes, which has 546 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on May 18, 2026.
Source: Tommy-yw/RunbookHermes on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.