{"repo":"alexgreensh/repo-forensics","free":true,"listed":false,"github":"https://github.com/alexgreensh/repo-forensics","clone":"git clone https://github.com/alexgreensh/repo-forensics.git","description":"Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.","language":"Python","stars":155,"topics":["forensics","security-tools","agent-skill","claude-skills","openclaw-skills","security-audit","security-scanner","agent-security","agent-skills","ai-agent-security"],"license":null,"category":"mcp-servers","readme_excerpt":"Repo Forensics npm audit for AI-agent plugins, skills, and MCP servers. Audit untrusted repos before they touch your agent. Fully local, self-updating detection, zero dependencies, zero telemetry. --- That npm package Cursor added to your lockfile. The GitHub Actions workflow someone contributed in a PR. The MCP server with 500 downloads. The Claude Code skill someone linked in Discord. The ClawHub extension your OpenClaw agent auto-installed. The Codex plugin you grabbed from GitHub. Did you vet any of them? Nobody does. The vetting step doesn't exist. 1,184 malicious skills found on ClawHub in one campaign. Snyk ToxicSkills research shows 36.8% of agent skills have security flaws. You find something useful, you install it. It runs with your credentials, your file access, your session context. If it's designed to exfiltrate data, it does it quietly while you're using it for something else entirely. You won't feel it. There are no symptoms. Repo Forensics is the vetting step. Audit any repo, skill, MCP server, or plugin before it touches your machine. Works across the AI agent ecosystem: Claude Code, OpenClaw, Codex, Cursor, NanoClaw, or anything that installs third-party code. 27 scanners, runtime behavior prediction, ClawHavoc campaign detection. Runs in seconds. Your code never leaves your machine. Zero dependencies. No cloud API. No telemetry. Unlike mcp-scan, nothing is uploaded anywhere. It doesn't stop at install. Every git pull , npm update , pnpm update , bun update ","default_branch":null,"files":null,"tree":[],"storefront":"/r/alexgreensh","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/alexgreensh/repo-forensics/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}