convert-ocsf-to-sarif
Installation
SKILL.md
convert-ocsf-to-sarif
Cross-vendor view-layer skill: takes OCSF 1.8 Detection Findings (class 2004) on stdin and emits a single SARIF 2.1.0 document on stdout. Built once, used by every detection-engineering pipeline that wants to surface findings in GitHub's Security tab.
Wire contract
Input: JSONL of OCSF Detection Findings produced by any detect-* skill in this repo.
Output: A single SARIF 2.1.0 JSON document (one runs[] entry, results array containing every input finding). The document validates against https://docs.oasis-open.org/sarif/sarif/v2.1.0/cs01/schemas/sarif-schema-2.1.0.json.