alexgreensh/Repo Forensics

Deep security auditing for repositories, AI agent skills, and MCP servers

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 7, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: alexgreensh/repo-forensics@d129c33712b78d7b61479906322b766d27b1cfbb # v2.12.1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathPath to repository to scan (default: workspace root)no.
modeScan mode: full or skill-scannofull
formatOutput format: text, json, or summarynotext
update-iocsPull latest IOC database before scanningnofalse
watchEnable file integrity baseline trackingnofalse
namedescription
exit-codeScanner exit code (0=clean, 1=high/medium, 2=critical)
findings-countTotal number of findings