convert-ocsf-to-mermaid-attack-flow
Installation
SKILL.md
convert-ocsf-to-mermaid-attack-flow
Cross-vendor view-layer skill: takes OCSF 1.8 Detection Findings on stdin, emits a Mermaid flowchart on stdout. Built once, used by every detection-engineering pipeline that wants to surface findings in a PR comment, a README, or any Markdown surface that renders Mermaid (GitHub does so natively).
Output shape
A single Mermaid flowchart LR block. One node per actor, one node per target, one edge per finding. Edge labels carry the MITRE technique uid (e.g. T1611). Nodes are coloured by maximum severity observed for that node:
- Red — any finding involving this node was severity Critical (5) or Fatal (6)
- Orange — High (4)
- Yellow — Medium (3)
- Grey — Low (2), Informational (1), or Unknown (0)
The diagram is enclosed in triple backticks with a mermaid language tag so it renders inline on GitHub.