By alexgreensh
Audits AI-agent repositories, skills, plugins, and MCP servers for security threats like prompt injection, credential theft, and CVEs, with cross-ecosystem risk analysis and automated scanning on session start and before/after Bash tool calls.
The agent stack you have already installed is your biggest blind spot.
Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA KEV (actively exploited) vulns, and 2026 attack patterns. Not for fixing vulnerabilities or pentesting.
Executes bash commands
Hook triggers when Bash tool is used
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Audit untrusted repos before they touch your agent. Fully local, self-updating detection, zero dependencies, zero telemetry.
/plugin marketplace add alexgreensh/repo-forensics
/plugin install repo-forensics@alexgreensh-repo-forensics
Hooks auto-wire on install. Every git clone, npm install, pip install is scanned automatically. Known-malicious packages are blocked before execution.
Install the plugin via the Codex marketplace. Hooks auto-wire from plugin.json. Same three hooks as Claude Code: PreToolUse (IOC gate), PostToolUse (auto-scan), SessionStart (security scan).
codex plugin marketplace add .
codex plugin add repo-forensics@alexgreensh-repo-forensics
For a local checkout/manual wire-up:
python3 scripts/codex_install.py
# restart Codex, then prove Codex registered the hooks
python3 scripts/codex_install.py --verify --require-registered
Codex v0.137+ inventory uses codex plugin list --json when available, falling back to filesystem manifests on older installs.
Install the plugin, then wire hooks:
python3 scripts/openclaw_install.py
npx claudepluginhub alexgreensh/repo-forensics --plugin repo-forensicsAudit, fix, and monitor Claude Code context window usage. Find the ghost tokens.
Complete collection of battle-tested Claude Code configs from an Anthropic hackathon winner - agents, skills, hooks, and rules evolved over 10+ months of intensive daily use
Efficient skill management system with progressive discovery — 410+ production-ready skills across 33+ domains
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses