Repo Forensics v2
Deep security auditing for repositories, AI agent skills, and MCP servers.
Highlights
- Auto-scan hook (v2): PostToolUse hook auto-triggers on
git clone, git pull, pip install, npm install/update, gem install/update, brew install/upgrade, etc. Zero-overhead for non-matching commands.
- Pre-execution gate (v2.6): PreToolUse hook blocks known-malicious packages and pipe-to-shell commands BEFORE execution. IOC-only, <10ms latency, no subprocess calls.
- Session security scanner (v2.6.3): SessionStart hook detects updated plugins/skills/MCP servers, refreshes threat databases daily, runs fast IOC check + full 19-scanner deep scan on changed items. Sub-1ms when nothing changed.
- .pth file injection detection (v2): Detects liteLLM-style Python startup injection attacks (exec/eval/base64/known IOC filenames)
- Transitive dependency scanning (v2): Deep-parses
package-lock.json, yarn.lock, poetry.lock, Pipfile.lock for supply chain IOCs
- DAST scanner (
scan_dast.py): Dynamic analysis of Claude Code hooks with 8 malicious payload types, sandboxed execution
- File integrity monitor (
scan_integrity.py): SHA256 baselines for critical config files, drift detection with --watch
- IOC auto-update (
--update-iocs): Pull latest indicators of compromise from remote feed
- Installation verification (
--verify-install): Verify repo-forensics itself hasn't been tampered with
- GitHub Actions (
action.yml): CI/CD integration for automated security gating
- Runtime behavior prediction (
scan_runtime_dynamism.py): Detects code that changes behavior after install: dynamic imports, fetch-then-execute, self-modification, time bombs, dynamic tool descriptions
- Manifest drift detection (
scan_manifest_drift.py): Compares declared vs actual dependencies, catches phantom deps, runtime installs, conditional import+install fallbacks
- MCP rug pull detection: Tool descriptions sourced from database, network, env vars, or conditional logic
- Enhanced AST analysis: 12 patterns including marshal.loads, types.CodeType, sys.addaudithook, bytes decode obfuscation, self-modification
- Test suite: 773 pytest tests covering all scanners
- OpenClaw/ClawHub scanning: Auto-detects OpenClaw skills, validates frontmatter, tools.json, SOUL.md, .clawhubignore
- Anti-forensics detection (v2): Self-deleting installers, package.json overwrite, version mismatch (Axios supply chain pattern)
- Compromised version detection (v2): Flags known-bad versions of legitimate packages (Axios 1.14.1/0.30.4, liteLLM 1.82.8)
- Suspicious npm scope detection (v2): Flags systematic MCP server forking campaigns (iflow-mcp)
- Host IOC scanning (v2): Known RAT binary paths, C2 domains, malicious file hashes
- CVE-2026-33068 detection (v2): Workspace trust bypass via bypassPermissions in Claude Code settings
- Post-incident forensics (v2.2): npm cache/log artifacts, RAT binary detection, C2 persistence, node_modules traces that survive dropper self-cleanup
- Supply chain hardening (v2.2): .npmrc scanning, missing lockfile detection, git/HTTP dep flagging, hostname bypass fix, unbounded Python range detection, install script severity elevation
- Devcontainer security scanning (v2.6.5): JSON-based analysis of devcontainer.json for host secret mounts, container escape vectors, localEnv interpolation, lifecycle command risks, and untrusted features
- Framework env prefix leak detection (v2.6.5): Catches secrets exposed to browser bundles via NEXT_PUBLIC_, REACT_APP_, VITE_, EXPO_PUBLIC_, GATSBY_, NX_PUBLIC_ prefixes
- process.env exposure detection (v2.6.5): Flags console.log(process.env), JSON.stringify(process.env), and crash report env dumps
- Docker ARG secret detection (v2.6.5): Catches secrets passed via ARG directives (permanently visible in docker history)
- 1Password/Vault token detection (v2.6.5): OP_CONNECT_TOKEN, ops_ service account tokens, hvs. Vault tokens
- 19 scanners with 21 correlation rules
When to Use
- Auditing a new repo or dependency before adding it to your project
- Vetting AI skills/plugins before installation (prompt injection, credential theft, backdoors)
- Auditing MCP servers for tool poisoning, SQL injection, config risks
- Security review when someone asks "is this code secure?"
- Forensic investigation of a suspected compromise
- CI/CD gating with machine-readable output and exit codes
- Hook security testing to verify Claude Code hooks handle malicious input safely
Quick Start
Full audit (all 19 scanners):
./scripts/run_forensics.sh /path/to/repo
Focused AI skill scan (10 scanners, faster):
./scripts/run_forensics.sh /path/to/repo --skill-scan
With IOC update and integrity monitoring:
./scripts/run_forensics.sh /path/to/repo --update-iocs --watch
Verify your installation:
./scripts/run_forensics.sh /path/to/repo --verify-install
JSON output for automation:
./scripts/run_forensics.sh /path/to/repo --format json
Severity System
| Level |
Score |
Meaning |
Exit Code |
| CRITICAL |
4 |
Active threat, immediate action required |
2 |
| HIGH |
3 |
Significant risk, investigate promptly |
1 |
| MEDIUM |
2 |
Potential issue, review recommended |
1 |
| LOW |
1 |
Informational, may be false positive |
0 |
Scanners
| Scanner |
What It Detects |
Mode |
| runtime_dynamism |
Dynamic imports, fetch-then-execute, self-modification, time bombs, dynamic tool descriptions |
skill + full |
| manifest_drift |
Phantom dependencies, runtime package installs, conditional import+install, declared-but-unused deps |
skill + full |
| skill_threats |
Prompt injection, unicode smuggling, prerequisite attacks, ClickFix, MCP tool injection |
skill + full |
| agent_skills |
SKILL.md frontmatter abuse, tools.json FSP, agent config injection (SOUL.md/AGENTS.md/CLAUDE.md), .clawhubignore bypass, ClawHavoc IOCs. Covers Claude Code, OpenClaw, Codex, Cursor, MCP. |
skill + full |
| mcp_security |
SQL injection to prompt escalation, tool poisoning, rug pull enablers, config CVEs |
skill + full |
| dataflow |
Source-to-sink taint tracking (env vars to network calls), cross-file import taint |
skill + full |
| secrets |
50+ patterns: API keys, tokens, private keys, database URIs, JWTs, framework env prefix leaks, 1Password/Vault tokens, .env variant files |
skill + full |
| sast |
Dangerous functions, injection, shell execution across 8 languages, process.env exposure, path traversal |
skill + full |
| lifecycle |
NPM hooks + Python setup.py/pyproject.toml cmdclass overrides + anti-forensics (self-deleting installers, package.json overwrite) |
skill + full |
| integrity |
SHA256 baselines for .claude/settings.json, CLAUDE.md, hook scripts. Drift detection with --watch |
full |
| dast |
Dynamic hook testing: 8 payload types (injection, traversal, amplification, env leak) in sandbox |
full |
| entropy |
Per-string Shannon entropy, base64 blocks, hex strings (combo detection) |
full |
| infra |
Docker (ENV/ARG secrets, .env COPY), K8s, GitHub Actions, Claude Code config (CVE-2025-59536, CVE-2026-21852, CVE-2026-33068) |
full |
| devcontainer |
JSON-based devcontainer.json analysis: host mounts, privileged mode, docker.sock, remoteEnv localEnv interpolation, lifecycle commands, untrusted features |
skill + full |
| dependencies |
NPM + Python typosquatting, l33t normalization, IOC packages (SANDWORM_MODE 2026), compromised version detection (Axios, liteLLM), suspicious scope detection (iflow-mcp) |
full |
| ast_analysis |
Python AST: obfuscated exec chains, __reduce__ backdoors, marshal/types bytecode, audit hook abuse, self-modification |
full |
| binary |
Executables hidden as images/text files |
full |
| git_forensics |
Time anomalies, GPG signature issues, identity inconsistencies |
full |
Dynamic Analysis (DAST)
The scan_dast.py scanner executes hook scripts with malicious payloads in a sandboxed subprocess:
8 payload types:
- Prompt injection in tool input
- Path traversal in file arguments
- Command injection via backticks/subshell
- Oversized input (amplification test)
- Unicode smuggling in arguments
- Environment variable exfiltration attempt
- Shell metacharacter injection
- Null byte injection
Safety: All execution uses subprocess with 5s timeout, stdout/stderr capture, scrubbed environment, temp directory isolation, no shell=True.
File Integrity Monitor
The scan_integrity.py scanner protects critical configuration files:
- SHA256 baselines for
.claude/settings.json, CLAUDE.md, .mcp.json, hook scripts
--watch mode: Creates baseline on first run, alerts on drift on subsequent runs
- Detects dangerous hook commands (curl, wget, eval, base64, /dev/tcp)
- Flags executable config files (unusual permission bits)
CVE + CISA KEV Auto-Enrichment (v2.6)
The dependency scanner automatically enriches findings with live vulnerability data:
- OSV (Open Source Vulnerabilities): Every pinned
(ecosystem, package, version) found in a manifest or lockfile is queried against api.osv.dev. Matches emit a cve finding with CVSS-mapped severity and suggested fix versions.
- CISA KEV (Known Exploited Vulnerabilities): CVE aliases are cross-referenced against the CISA KEV catalog — CVEs confirmed actively exploited in the wild. Any match is escalated to CRITICAL severity (category
cve-kev) regardless of CVSS, because exploitation in the wild is the strongest prioritization signal.
- Caches: KEV catalog is cached 24h (
~/.cache/repo-forensics/kev.json). OSV per-package queries cache 24h (~/.cache/repo-forensics/osv-queries.json, LRU-capped at 4000 entries). Both files are written atomically with mode 0o600.
- Security: Feed URLs are hardcoded constants. No user-overridable URL at the public API (SSRF guardrail). Response size caps, HTTPS-only fetch, fail-closed CVE ID validation, and oversized-response rejection. A malformed or hostile feed returns an empty result rather than crashing the scanner.
- Offline mode:
--offline uses cached data only; --no-vulns disables the feature entirely.
- CLI:
--update-vulns refreshes the KEV catalog before scanning. Standalone tool: python3 scripts/vuln_feed.py --query npm lodash 4.17.20.
IOC Auto-Update
The --update-iocs flag pulls latest indicators of compromise from a hosted JSON feed:
- C2 IP addresses, malicious domains, known-bad packages
- Cached locally in
.forensics-iocs.json (24h TTL)
- Falls back to hardcoded IOCs when offline
- Managed by
ioc_manager.py (--show to inspect, --update to pull)
Installation Verification
The --verify-install flag checks that repo-forensics itself hasn't been tampered with:
- Compares all skill files against
checksums.json (SHA256)
- Detects modified, missing, or unexpected files
- Run
verify_install.py --generate at release time to create checksums
AI Skill Threat Detection
The scan_skill_threats.py scanner detects 10 categories of AI agent skill attacks:
- Prompt injection directives ("ignore previous instructions", persona reassignment)
- Invisible unicode smuggling (zero-width chars, RTL override, Cyrillic + Greek homoglyphs)
- Prerequisite red flags (curl-pipe-bash, password-protected archives, xattr -c)
- Credential exfiltration (bulk env access + network calls, webhook services)
- Persistence mechanisms (LaunchAgents, crontab, shell RC modifications)
- Scope escalation (accessing ~/.ssh, browser data, Keychain, other skills)
- Stealth directives ("do not log", output suppression with background exec)
- Known campaign IOCs (C2 IPs from ClawHavoc, SANDWORM_MODE, Telegram/Discord exfil)
- ClickFix / sleeper malware (curl|base64-d|bash delivery, glot.io pastebins, SKILL.md prereqs)
- MCP tool description injection (Invariant Labs
<IMPORTANT> tag, "note to the AI", hidden instructions in JSON description fields)
MCP Attack Surface
The scan_mcp_security.py scanner covers MCP-specific attack vectors discovered in 2025-2026:
Tool Poisoning Attack (TPA)
Hidden instructions injected into tool description fields load into LLM context without user visibility. Canonical pattern: <IMPORTANT> tag (Invariant Labs, 2025).
SQL Injection to Stored Prompt Injection
SQL injection in MCP server code can write malicious prompts into databases that are later retrieved and executed by agents (Trend Micro TrendAI, May 2025).
Configuration Risks
- CVE-2025-59536 (CVSS 8.7): Claude Code hooks execute before trust dialog, RCE via
.claude/settings.json
- CVE-2026-21852 (CVSS 7.5):
ANTHROPIC_BASE_URL override exfiltrates API keys
- CVE-2025-49596 (CVSS 9.4): MCP Inspector DNS rebinding via
0.0.0.0 binding
- CVE-2025-6514 (CVSS 9.6): mcp-remote OAuth command injection
- CVE-2026-33068 (CVSS 7.7): Workspace trust bypass via
bypassPermissions in .claude/settings.json
enableAllProjectMcpServers: true: Bypasses per-server consent dialogs
Tool Shadowing
Cross-tool contamination where one tool's description instructs the LLM to modify behavior of other tools (Invariant Labs 2025).
Rug Pull Enablers
Tool descriptions sourced from mutable data (database queries, network requests, environment variables, runtime file loads). These don't prove malicious intent but flag that tool behavior can change without code changes (Lukas Kania, March 2026; OWASP MCP07).
Runtime Behavior Prediction
The scan_runtime_dynamism.py scanner detects static indicators that code will change behavior after install:
- Dynamic imports:
importlib.import_module(variable), __import__(env_var), require(variable), ES import(variable)
- Fetch-then-execute:
requests.get(url).text piped to eval(), runtime pip install/npm install, download-and-run scripts
- Self-modification:
types.FunctionType(), types.CodeType(), marshal.loads(), open(__file__, 'w'), SourcelessFileLoader (CVE-2026-2297)
- Time bombs:
datetime.now() > datetime(2026,6,1), unix timestamp comparisons, counter-based activation, probabilistic triggers
- Dynamic tool descriptions: MCP description from
db.query(), requests.get(), os.environ, conditional descriptions
Uses both regex patterns and Python AST analysis for reliable detection.
Manifest Drift Detection
The scan_manifest_drift.py scanner compares what a package DECLARES vs what it actually USES:
- Phantom dependencies: Module imported in code but not in
requirements.txt/package.json
- Runtime package installs:
subprocess.run(["pip", "install", pkg]) in code
- Conditional import+install:
try: import X except: os.system("pip install X")
- Declared but unused: Package in manifest but never imported (potential dependency confusion decoy)
Supports Python (requirements.txt, pyproject.toml, setup.py) and Node.js (package.json).
Correlation Engine
The correlation engine (forensics_core.py) identifies compound threats across 14 rules:
- Environment/credential access + network call = Potential Data Exfiltration (critical)
- Base64 encoding + exec/eval = Obfuscated Code Execution (critical)
- Sensitive file read + network call = Credential Theft Pattern (high)
- Prompt injection + code execution = Prompt-Assisted Code Execution (critical)
- Lifecycle hook + network call = Install-Time Exfiltration (critical)
- SQL injection + MCP/skill_threats finding = SQL Injection Prompt Escalation (critical)
- Tool metadata poisoning + code execution = Tool Metadata Poisoning Chain (critical)
- Unicode smuggling + prompt injection in docs = Hidden Instruction Attack in Documentation (high)
- Dynamic import + network fetch = Deferred Payload Loading (critical)
- Time/counter trigger + exec/eval = Time-Triggered Malware (critical)
- Dynamic tool description + MCP server = MCP Rug Pull Enabler (high)
- Phantom dependency + network call = Shadow Dependency with Network Access (critical)
- Pipe exfiltration + network sink = Shell Script Data Exfiltration Chain (critical)
- Tools.json poisoning + prompt injection = Agent Skill Compound Attack (critical)
Configuration
Create .forensicsignore in the repo root to suppress false positives:
tests/fixtures/secrets.json
legacy/unsafe_code/*
src/config/dev_keys.py
Note: .forensicsignore itself is scanned for attacker-planted wildcard suppression patterns.
Output Formats
--format text (default): Colored human-readable output with severity tags
--format json: Machine-readable JSON array of Finding objects
--format summary: Counts only (for CI/CD scripting)
GitHub Actions
Add to your workflow:
- uses: alexgreensh/repo-forensics@v1
with:
mode: full
format: text
update-iocs: true
Research Sources
See references/research_sources.md for full credits and links to the published research that informed this skill's threat detection capabilities.
1---2name: repo-forensics3description: Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA KEV (actively exploited) vulns, and 2026 attack patterns. Not for fixing vulnerabilities or pentesting.4---5
6<!-- repo-forensics v2 | built by Alex Greenshpun | https://linkedin.com/in/alexgreensh -->
7
8# Repo Forensics v2
9
10Deep security auditing for repositories, AI agent skills, and MCP servers.
11
12## Highlights
13
14- **Auto-scan hook** (v2): PostToolUse hook auto-triggers on `git clone`, `git pull`, `pip install`, `npm install/update`, `gem install/update`, `brew install/upgrade`, etc. Zero-overhead for non-matching commands.
15- **Pre-execution gate** (v2.6): PreToolUse hook blocks known-malicious packages and pipe-to-shell commands BEFORE execution. IOC-only, <10ms latency, no subprocess calls.
16- **Session security scanner** (v2.6.3): SessionStart hook detects updated plugins/skills/MCP servers, refreshes threat databases daily, runs fast IOC check + full 19-scanner deep scan on changed items. Sub-1ms when nothing changed.
17- **.pth file injection detection** (v2): Detects liteLLM-style Python startup injection attacks (exec/eval/base64/known IOC filenames)
18- **Transitive dependency scanning** (v2): Deep-parses `package-lock.json`, `yarn.lock`, `poetry.lock`, `Pipfile.lock` for supply chain IOCs
19- **DAST scanner** (`scan_dast.py`): Dynamic analysis of Claude Code hooks with 8 malicious payload types, sandboxed execution
20- **File integrity monitor** (`scan_integrity.py`): SHA256 baselines for critical config files, drift detection with `--watch`
21- **IOC auto-update** (`--update-iocs`): Pull latest indicators of compromise from remote feed
22- **Installation verification** (`--verify-install`): Verify repo-forensics itself hasn't been tampered with
23- **GitHub Actions** (`action.yml`): CI/CD integration for automated security gating
24- **Runtime behavior prediction** (`scan_runtime_dynamism.py`): Detects code that changes behavior after install: dynamic imports, fetch-then-execute, self-modification, time bombs, dynamic tool descriptions
25- **Manifest drift detection** (`scan_manifest_drift.py`): Compares declared vs actual dependencies, catches phantom deps, runtime installs, conditional import+install fallbacks
26- **MCP rug pull detection**: Tool descriptions sourced from database, network, env vars, or conditional logic
27- **Enhanced AST analysis**: 12 patterns including marshal.loads, types.CodeType, sys.addaudithook, bytes decode obfuscation, self-modification
28- **Test suite**: 773 pytest tests covering all scanners
29- **OpenClaw/ClawHub scanning**: Auto-detects OpenClaw skills, validates frontmatter, tools.json, SOUL.md, .clawhubignore
30- **Anti-forensics detection** (v2): Self-deleting installers, package.json overwrite, version mismatch (Axios supply chain pattern)
31- **Compromised version detection** (v2): Flags known-bad versions of legitimate packages (Axios 1.14.1/0.30.4, liteLLM 1.82.8)
32- **Suspicious npm scope detection** (v2): Flags systematic MCP server forking campaigns (iflow-mcp)
33- **Host IOC scanning** (v2): Known RAT binary paths, C2 domains, malicious file hashes
34- **CVE-2026-33068 detection** (v2): Workspace trust bypass via bypassPermissions in Claude Code settings
35- **Post-incident forensics** (v2.2): npm cache/log artifacts, RAT binary detection, C2 persistence, node_modules traces that survive dropper self-cleanup
36- **Supply chain hardening** (v2.2): .npmrc scanning, missing lockfile detection, git/HTTP dep flagging, hostname bypass fix, unbounded Python range detection, install script severity elevation
37- **Devcontainer security scanning** (v2.6.5): JSON-based analysis of devcontainer.json for host secret mounts, container escape vectors, localEnv interpolation, lifecycle command risks, and untrusted features
38- **Framework env prefix leak detection** (v2.6.5): Catches secrets exposed to browser bundles via NEXT_PUBLIC_, REACT_APP_, VITE_, EXPO_PUBLIC_, GATSBY_, NX_PUBLIC_ prefixes
39- **process.env exposure detection** (v2.6.5): Flags console.log(process.env), JSON.stringify(process.env), and crash report env dumps
40- **Docker ARG secret detection** (v2.6.5): Catches secrets passed via ARG directives (permanently visible in docker history)
41- **1Password/Vault token detection** (v2.6.5): OP_CONNECT_TOKEN, ops_ service account tokens, hvs. Vault tokens
42- **19 scanners** with 21 correlation rules
43
44## When to Use
45
46- **Auditing a new repo or dependency** before adding it to your project
47- **Vetting AI skills/plugins** before installation (prompt injection, credential theft, backdoors)
48- **Auditing MCP servers** for tool poisoning, SQL injection, config risks
49- **Security review** when someone asks "is this code secure?"
50- **Forensic investigation** of a suspected compromise
51- **CI/CD gating** with machine-readable output and exit codes
52- **Hook security testing** to verify Claude Code hooks handle malicious input safely
53
54## Quick Start
55
56Full audit (all 19 scanners):
57```bash
58./scripts/run_forensics.sh /path/to/repo
59```
60
61Focused AI skill scan (10 scanners, faster):
62```bash
63./scripts/run_forensics.sh /path/to/repo --skill-scan
64```
65
66With IOC update and integrity monitoring:
67```bash
68./scripts/run_forensics.sh /path/to/repo --update-iocs --watch
69```
70
71Verify your installation:
72```bash
73./scripts/run_forensics.sh /path/to/repo --verify-install
74```
75
76JSON output for automation:
77```bash
78./scripts/run_forensics.sh /path/to/repo --format json
79```
80
81## Severity System
82
83| Level | Score | Meaning | Exit Code |
84|-------|-------|---------|-----------|
85| CRITICAL | 4 | Active threat, immediate action required | 2 |
86| HIGH | 3 | Significant risk, investigate promptly | 1 |
87| MEDIUM | 2 | Potential issue, review recommended | 1 |
88| LOW | 1 | Informational, may be false positive | 0 |
89
90## Scanners
91
92| Scanner | What It Detects | Mode |
93|---------|----------------|------|
94| **runtime_dynamism** | Dynamic imports, fetch-then-execute, self-modification, time bombs, dynamic tool descriptions | skill + full |
95| **manifest_drift** | Phantom dependencies, runtime package installs, conditional import+install, declared-but-unused deps | skill + full |
96| **skill_threats** | Prompt injection, unicode smuggling, prerequisite attacks, ClickFix, MCP tool injection | skill + full |
97| **agent_skills** | SKILL.md frontmatter abuse, tools.json FSP, agent config injection (SOUL.md/AGENTS.md/CLAUDE.md), .clawhubignore bypass, ClawHavoc IOCs. Covers Claude Code, OpenClaw, Codex, Cursor, MCP. | skill + full |
98| **mcp_security** | SQL injection to prompt escalation, tool poisoning, rug pull enablers, config CVEs | skill + full |
99| **dataflow** | Source-to-sink taint tracking (env vars to network calls), cross-file import taint | skill + full |
100| **secrets** | 50+ patterns: API keys, tokens, private keys, database URIs, JWTs, framework env prefix leaks, 1Password/Vault tokens, .env variant files | skill + full |
101| **sast** | Dangerous functions, injection, shell execution across 8 languages, process.env exposure, path traversal | skill + full |
102| **lifecycle** | NPM hooks + Python setup.py/pyproject.toml cmdclass overrides + anti-forensics (self-deleting installers, package.json overwrite) | skill + full |
103| **integrity** | SHA256 baselines for .claude/settings.json, CLAUDE.md, hook scripts. Drift detection with `--watch` | full |
104| **dast** | Dynamic hook testing: 8 payload types (injection, traversal, amplification, env leak) in sandbox | full |
105| **entropy** | Per-string Shannon entropy, base64 blocks, hex strings (combo detection) | full |
106| **infra** | Docker (ENV/ARG secrets, .env COPY), K8s, GitHub Actions, Claude Code config (CVE-2025-59536, CVE-2026-21852, CVE-2026-33068) | full |
107| **devcontainer** | JSON-based devcontainer.json analysis: host mounts, privileged mode, docker.sock, remoteEnv localEnv interpolation, lifecycle commands, untrusted features | skill + full |
108| **dependencies** | NPM + Python typosquatting, l33t normalization, IOC packages (SANDWORM_MODE 2026), compromised version detection (Axios, liteLLM), suspicious scope detection (iflow-mcp) | full |
109| **ast_analysis** | Python AST: obfuscated exec chains, `__reduce__` backdoors, marshal/types bytecode, audit hook abuse, self-modification | full |
110| **binary** | Executables hidden as images/text files | full |
111| **git_forensics** | Time anomalies, GPG signature issues, identity inconsistencies | full |
112
113## Dynamic Analysis (DAST)
114
115The `scan_dast.py` scanner executes hook scripts with malicious payloads in a sandboxed subprocess:
116
117**8 payload types:**
1181. Prompt injection in tool input
1192. Path traversal in file arguments
1203. Command injection via backticks/subshell
1214. Oversized input (amplification test)
1225. Unicode smuggling in arguments
1236. Environment variable exfiltration attempt
1247. Shell metacharacter injection
1258. Null byte injection
126
127**Safety:** All execution uses subprocess with 5s timeout, stdout/stderr capture, scrubbed environment, temp directory isolation, no shell=True.
128
129## File Integrity Monitor
130
131The `scan_integrity.py` scanner protects critical configuration files:
132
133- SHA256 baselines for `.claude/settings.json`, `CLAUDE.md`, `.mcp.json`, hook scripts
134- **`--watch` mode**: Creates baseline on first run, alerts on drift on subsequent runs
135- Detects dangerous hook commands (curl, wget, eval, base64, /dev/tcp)
136- Flags executable config files (unusual permission bits)
137
138## CVE + CISA KEV Auto-Enrichment (v2.6)
139
140The dependency scanner automatically enriches findings with live vulnerability data:
141
142- **OSV (Open Source Vulnerabilities):** Every pinned `(ecosystem, package, version)` found in a manifest or lockfile is queried against `api.osv.dev`. Matches emit a `cve` finding with CVSS-mapped severity and suggested fix versions.
143- **CISA KEV (Known Exploited Vulnerabilities):** CVE aliases are cross-referenced against the CISA KEV catalog — CVEs confirmed actively exploited in the wild. Any match is escalated to **CRITICAL** severity (category `cve-kev`) regardless of CVSS, because exploitation in the wild is the strongest prioritization signal.
144- **Caches:** KEV catalog is cached 24h (`~/.cache/repo-forensics/kev.json`). OSV per-package queries cache 24h (`~/.cache/repo-forensics/osv-queries.json`, LRU-capped at 4000 entries). Both files are written atomically with mode 0o600.
145- **Security:** Feed URLs are hardcoded constants. No user-overridable URL at the public API (SSRF guardrail). Response size caps, HTTPS-only fetch, fail-closed CVE ID validation, and oversized-response rejection. A malformed or hostile feed returns an empty result rather than crashing the scanner.
146- **Offline mode:** `--offline` uses cached data only; `--no-vulns` disables the feature entirely.
147- **CLI:** `--update-vulns` refreshes the KEV catalog before scanning. Standalone tool: `python3 scripts/vuln_feed.py --query npm lodash 4.17.20`.
148
149## IOC Auto-Update
150
151The `--update-iocs` flag pulls latest indicators of compromise from a hosted JSON feed:
152
153- C2 IP addresses, malicious domains, known-bad packages
154- Cached locally in `.forensics-iocs.json` (24h TTL)
155- Falls back to hardcoded IOCs when offline
156- Managed by `ioc_manager.py` (`--show` to inspect, `--update` to pull)
157
158## Installation Verification
159
160The `--verify-install` flag checks that repo-forensics itself hasn't been tampered with:
161
162- Compares all skill files against `checksums.json` (SHA256)
163- Detects modified, missing, or unexpected files
164- Run `verify_install.py --generate` at release time to create checksums
165
166## AI Skill Threat Detection
167
168The `scan_skill_threats.py` scanner detects 10 categories of AI agent skill attacks:
169
1701. **Prompt injection directives** ("ignore previous instructions", persona reassignment)
1712. **Invisible unicode smuggling** (zero-width chars, RTL override, Cyrillic + Greek homoglyphs)
1723. **Prerequisite red flags** (curl-pipe-bash, password-protected archives, xattr -c)
1734. **Credential exfiltration** (bulk env access + network calls, webhook services)
1745. **Persistence mechanisms** (LaunchAgents, crontab, shell RC modifications)
1756. **Scope escalation** (accessing ~/.ssh, browser data, Keychain, other skills)
1767. **Stealth directives** ("do not log", output suppression with background exec)
1778. **Known campaign IOCs** (C2 IPs from ClawHavoc, SANDWORM_MODE, Telegram/Discord exfil)
1789. **ClickFix / sleeper malware** (curl|base64-d|bash delivery, glot.io pastebins, SKILL.md prereqs)
17910. **MCP tool description injection** (Invariant Labs `<IMPORTANT>` tag, "note to the AI", hidden instructions in JSON description fields)
180
181## MCP Attack Surface
182
183The `scan_mcp_security.py` scanner covers MCP-specific attack vectors discovered in 2025-2026:
184
185### Tool Poisoning Attack (TPA)
186Hidden instructions injected into tool `description` fields load into LLM context without user visibility. Canonical pattern: `<IMPORTANT>` tag (Invariant Labs, 2025).
187
188### SQL Injection to Stored Prompt Injection
189SQL injection in MCP server code can write malicious prompts into databases that are later retrieved and executed by agents (Trend Micro TrendAI, May 2025).
190
191### Configuration Risks
192- **CVE-2025-59536** (CVSS 8.7): Claude Code hooks execute before trust dialog, RCE via `.claude/settings.json`
193- **CVE-2026-21852** (CVSS 7.5): `ANTHROPIC_BASE_URL` override exfiltrates API keys
194- **CVE-2025-49596** (CVSS 9.4): MCP Inspector DNS rebinding via `0.0.0.0` binding
195- **CVE-2025-6514** (CVSS 9.6): mcp-remote OAuth command injection
196- **CVE-2026-33068** (CVSS 7.7): Workspace trust bypass via `bypassPermissions` in `.claude/settings.json`
197- **`enableAllProjectMcpServers: true`**: Bypasses per-server consent dialogs
198
199### Tool Shadowing
200Cross-tool contamination where one tool's description instructs the LLM to modify behavior of other tools (Invariant Labs 2025).
201
202### Rug Pull Enablers
203Tool descriptions sourced from mutable data (database queries, network requests, environment variables, runtime file loads). These don't prove malicious intent but flag that tool behavior can change without code changes (Lukas Kania, March 2026; OWASP MCP07).
204
205## Runtime Behavior Prediction
206
207The `scan_runtime_dynamism.py` scanner detects static indicators that code will change behavior after install:
208
2091. **Dynamic imports**: `importlib.import_module(variable)`, `__import__(env_var)`, `require(variable)`, ES `import(variable)`
2102. **Fetch-then-execute**: `requests.get(url).text` piped to `eval()`, runtime `pip install`/`npm install`, download-and-run scripts
2113. **Self-modification**: `types.FunctionType()`, `types.CodeType()`, `marshal.loads()`, `open(__file__, 'w')`, `SourcelessFileLoader` (CVE-2026-2297)
2124. **Time bombs**: `datetime.now() > datetime(2026,6,1)`, unix timestamp comparisons, counter-based activation, probabilistic triggers
2135. **Dynamic tool descriptions**: MCP description from `db.query()`, `requests.get()`, `os.environ`, conditional descriptions
214
215Uses both regex patterns and Python AST analysis for reliable detection.
216
217## Manifest Drift Detection
218
219The `scan_manifest_drift.py` scanner compares what a package DECLARES vs what it actually USES:
220
221- **Phantom dependencies**: Module imported in code but not in `requirements.txt`/`package.json`
222- **Runtime package installs**: `subprocess.run(["pip", "install", pkg])` in code
223- **Conditional import+install**: `try: import X except: os.system("pip install X")`
224- **Declared but unused**: Package in manifest but never imported (potential dependency confusion decoy)
225
226Supports Python (requirements.txt, pyproject.toml, setup.py) and Node.js (package.json).
227
228## Correlation Engine
229
230The correlation engine (`forensics_core.py`) identifies compound threats across 14 rules:
231
2321. Environment/credential access + network call = **Potential Data Exfiltration** (critical)
2332. Base64 encoding + exec/eval = **Obfuscated Code Execution** (critical)
2343. Sensitive file read + network call = **Credential Theft Pattern** (high)
2354. Prompt injection + code execution = **Prompt-Assisted Code Execution** (critical)
2365. Lifecycle hook + network call = **Install-Time Exfiltration** (critical)
2376. SQL injection + MCP/skill_threats finding = **SQL Injection Prompt Escalation** (critical)
2387. Tool metadata poisoning + code execution = **Tool Metadata Poisoning Chain** (critical)
2398. Unicode smuggling + prompt injection in docs = **Hidden Instruction Attack in Documentation** (high)
2409. Dynamic import + network fetch = **Deferred Payload Loading** (critical)
24110. Time/counter trigger + exec/eval = **Time-Triggered Malware** (critical)
24211. Dynamic tool description + MCP server = **MCP Rug Pull Enabler** (high)
24312. Phantom dependency + network call = **Shadow Dependency with Network Access** (critical)
24413. Pipe exfiltration + network sink = **Shell Script Data Exfiltration Chain** (critical)
24514. Tools.json poisoning + prompt injection = **Agent Skill Compound Attack** (critical)
246
247## Configuration
248
249Create `.forensicsignore` in the repo root to suppress false positives:
250```text
251tests/fixtures/secrets.json
252legacy/unsafe_code/*
253src/config/dev_keys.py
254```
255
256Note: `.forensicsignore` itself is scanned for attacker-planted wildcard suppression patterns.
257
258## Output Formats
259
260- `--format text` (default): Colored human-readable output with severity tags
261- `--format json`: Machine-readable JSON array of Finding objects
262- `--format summary`: Counts only (for CI/CD scripting)
263
264## GitHub Actions
265
266Add to your workflow:
267```yaml
268- uses: alexgreensh/repo-forensics@v1
269 with:
270 mode: full
271 format: text
272 update-iocs: true
273```
274
275## Research Sources
276
277See `references/research_sources.md` for full credits and links to the published research that informed this skill's threat detection capabilities.