OSS Forensics
Supply-chain forensics for GitHub repos: deleted commits, force-pushes, IOCs.
hermes skills install official/security/oss-forensicsAbout
Supply-chain investigation for GitHub repositories — deleted-commit recovery, force-push detection, IOC extraction, multi-source evidence collection. Optional Hermes skill: `hermes skills install official/security/oss-forensics`. Indexed from the NousResearch/hermes-agent repo for discovery — Solid State has not audited this skill.
Vet a third-party agent skill before you install or run it. Checks provenance, license, pinning, hidden or injected instructions, dependency/supply-chain risks, and dangerous capabilities — then returns RUN / REVIEW / DO NOT RUN.
Security-first skill vetting for AI agents. Checks red flags, permission scope, suspicious patterns before install.
Passive domain recon: subdomains, SSL certs, WHOIS, DNS. Python stdlib only.
