Academy → Using HermesOfficial documentation · clear explanation

Oss Forensics — GitHub supply-chain forensics: recovery, IOCs, reporting

Oss Forensics — GitHub supply-chain forensics: recovery, IOCs, reporting

Developer19 minutes3 questions2026-08-09
The idea in one minute

Start with meaning, then move to detail.

This lesson explains Oss Forensics — GitHub supply-chain forensics: recovery, IOCs, reporting as part of Hermes internals and extension points. You will learn what it does, when it matters, and the smallest safe test that proves it works.

If you are new

If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?

For hands-on use

For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.

For specialists

For advanced readers, inspect Skill metadata, Reference: full SKILL.md, ⚠️ Anti-Hallucination Guardrails, then verify failure modes and version compatibility.

What do you need first?

Know Python, Git, and basic project structure before changing code.

What will you know?

A clear outcome before you read.

  • Understand Oss Forensics — GitHub supply-chain forensics: recovery, IOCs, reporting without assumed prior knowledge.
  • Separate the source description from what still needs testing in your environment.
  • Read the first command and identify its inputs and outputs before copying it.
Lesson terms

Short definitions before the details.

Skill
An instruction bundle that teaches Hermes a repeatable workflow without necessarily adding an external service.
Official page description

GitHub supply-chain forensics: recovery, IOCs, reporting

Topic map

What does the source say, and in what order?

  1. 01
    Skill metadata

    Start here to understand the core idea or structure.

  2. 02
    Reference: full SKILL.md

    Read this after the foundation, then connect it to the previous step.

  3. 03
    ⚠️ Anti-Hallucination Guardrails

    Read this after the foundation, then connect it to the previous step.

  4. 04
    Example Scenarios

    Read this after the foundation, then connect it to the previous step.

  5. 05
    Phase 0: Initialization

    Read this after the foundation, then connect it to the previous step.

  6. 06
    Phase 1: Prompt Parsing and IOC Extraction

    Read this after the foundation, then connect it to the previous step.

  7. 07
    Phase 2: Parallel Evidence Collection

    Read this after the foundation, then connect it to the previous step.

  8. 08
    Investigator 1: Local Git Investigator

    Read this after the foundation, then connect it to the previous step.

  9. 09
    Investigator 2: GitHub API Investigator

    Read this after the foundation, then connect it to the previous step.

  10. 10
    Investigator 3: Wayback Machine Investigator

    Finish here to verify the result and special cases.

Examples from the official page

Copy only after you understand the effect.

mkdir investigation_$(echo "REPO_NAME" | tr '/' '_') cd investigation_$(echo "REPO_NAME" | tr '/' '_')
python3 SKILL_DIR/scripts/evidence-store.py --store evidence.json list
cp SKILL_DIR/templates/forensic-report.md ./investigation-report.md
Try it now

Read the first command and identify its inputs and outputs before copying it.

Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.

Knowledge check

Three decisions before completion.

1. What is the source of truth when “Oss Forensics — GitHub supply-chain forensics: recovery, IOCs, reporting” changes?
2. What is the best way to apply this lesson?
3. What should happen before a step can modify files or an external account?