BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

repo-forensics

Skill Security Usable
Works inClaude Code
Usable Scanned — metadata only

Detects secrets, malware, and supply-chain risks in code repos before they reach production.

Automated Security scanner for GitHub repos, Agent Skills, Plugins, and MCP servers. 18 scanners. Zero dependencies. Keeps you and your agent safe.

144 starsFreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Detects secrets, malware, and supply-chain risks in code repos before they reach production. Reduces breach surface by scanning dependencies and agent configurations without requiring external services.

Security teams and engineering leads vetting third-party GitHub repos, MCP servers, or Claude plugins before integration.

Claude Code Claude Cowork Claude Chat

https://github.com/alexgreensh/repo-forensics

By alexgreensh

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
claude plugins install alexgreensh/repo-forensics

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.

First thing to try

After installing, paste this into Claude:

Help me pre-integration scan of public GitHub repos for exposed credentials
CostFree

Trust Signals Auto-scanned

Stars144Contributors7Last updated2026-07-25Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-25 · scanner v1

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 144 GitHub stars; 7 contributors; last commit 0d ago; license no license.

Things to check

  • Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
1/5
Versatility
3/5
Reliability
4/5
Security
4/5
Overall score2.70 / 5.00 UsableEvaluatedJul 2026
Scored from trust signals (evidence-eval-v1): 144 GitHub stars; 7 contributors; last commit 0d ago; license no license.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →