repo-forensics
Audit agent skills, plugins, and MCP repositories before they reach your tools.
- Stars
- 139
- Forks
- 19
- Updated
- Updated Jul 13, 2026
Audit agent skills, plugins, and MCP repositories before they reach your tools.
Repo Forensics scans untrusted agent repositories locally for prompt injection, malicious packages, MCP tool poisoning, credential access, data exfiltration, obfuscated execution, and compound attack chains. It can audit an existing agent stack or install hooks that block known package indicators before commands and run a broader review after clones or installs. Detection rules and vulnerability intelligence can be updated separately, and the scanner reports no telemetry.
Resource types
Use cases
Platforms
Audit backend risks and turn verified findings into prioritized fixes.
Audit authorized web applications through source review or black-box checks.
Runtime
Capabilities
Public GitHub facts last synced Jul 14, 2026.
Run supported always-on AI agents inside managed NVIDIA OpenShell sandboxes.
Plan and run authorized penetration tests with autonomous agents in an isolated environment.