PluginSecurity and privacy

repo-forensics

Audit agent skills, plugins, and MCP repositories before they reach your tools.

Stars
139
Forks
19
License
Custom / other
Updated
Updated Jul 13, 2026

Checking live repository facts…

Project overview

Repo Forensics scans untrusted agent repositories locally for prompt injection, malicious packages, MCP tool poisoning, credential access, data exfiltration, obfuscated execution, and compound attack chains. It can audit an existing agent stack or install hooks that block known package indicators before commands and run a broader review after clones or installs. Detection rules and vulnerability intelligence can be updated separately, and the scanner reports no telemetry.

Repository facts

Primary language
Python
License
Custom / other
Repository updated
Jul 13, 2026
Default branch
main

Resource types

Plugin

Use cases

Security and privacy

Platforms

Claude CodeCodexOpenClaw

Runtime

Command lineLocal

Capabilities

Security guardrailVerification and evals

Related projects

Browse more similar projects