repo-forensics — security grade SAFE, quality 69/100

Security audit verdict: SAFE · quality 69/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by alexgreensh · MCP Server · ★ 174

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is repo-forensics safe to install? View the security audit →

About repo-forensics

That MCP server with 500 downloads. The Claude Code skill someone linked in Discord. The ClawHub extension your OpenClaw agent auto-installed. The npm package Cursor added to your lockfile. The Codex plugin you grabbed from GitHub. Did you vet any of them? Nobody does. The vetting step doesn't exist. 1,184 malicious skills found on ClawHub in one campaign. 36.8% of agent skills have security flaws. You find something useful, you install it. It runs with your credentials, your file access, your session context. If it's designed to exfiltrate data, it does it quietly while you're using it for something else entirely. You won't feel it. There are no sy

agent-securityagent-skillagent-skillsai-agent-securityclaude-codeclaude-skillscodexdeveloper-toolsforensicsmcp-security

Quick Facts

Stars174
Forks27
LanguagePython
CategoryMCP Server
Quality Score68.9702127224776/100
Open Issues5
Last Updated2026-09-13
Created2026-02-27
Platformsclaude-code, codex, mcp, python
Est. Tokens~18k

repo-forensics alternative? Top 6 similar tools

Looking for a repo-forensics alternative? If you're comparing repo-forensics with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • hol-guard by hashgraph-online · ⭐ 634

    Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M

  • agent-security-scanner-mcp by sinewaveai · ⭐ 121

    Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (

  • claude-code-organizer by mcpware · ⭐ 283

    Dashboard to manage Claude Code memories, configs, and MCP servers — security scanner for tool poisoning, cont

  • claudepro-directory by JSONbored · ⭐ 217

    HeyClaude (formerly Claude Pro Directory) is a searchable collection of pre-built AI skills, agents, MCP serve

  • node9-proxy by node9-ai · ⭐ 214

    The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for

  • mcp-observatory by KryptosAI · ⭐ 139

    CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring befo

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is repo-forensics?

repo-forensics is Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.. It is categorized as a MCP Server with 174 GitHub stars.

What programming language is repo-forensics written in?

repo-forensics is primarily written in Python. It covers topics such as agent-security, agent-skill, agent-skills.

How do I install or use repo-forensics?

You can find installation instructions and usage details in the repo-forensics GitHub repository at github.com/alexgreensh/repo-forensics. The project has 174 stars and 27 forks, indicating an active community.

What are the best alternatives to repo-forensics?

The top alternatives to repo-forensics on Agent Skills Hub include hol-guard, agent-security-scanner-mcp, claude-code-organizer. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools