convert-ocsf-to-sarif
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates entirely locally to perform data transformation and contains no network-reaching code or external dependencies. It is authored by 'msaad00' and correctly references the vendor's own repository at 'github.com/msaad00/cloud-ai-security-skills' for tool information.
- [COMMAND_EXECUTION]: The script
src/convert.pyimplements a command-line interface usingargparsethat allows reading from and writing to arbitrary file paths provided by the user. This functionality is consistent with the skill's intended purpose as a conversion utility for security logs. - [PROMPT_INJECTION]: The skill processes untrusted OCSF JSONL logs, creating a surface for indirect prompt injection. Since the skill maps this data into a structured SARIF format for display in external security dashboards, the potential impact is restricted to deceptive content in those viewers, with no mechanism for execution within the skill itself. 1. Ingestion points:
src/convert.py(line 217) reads log data fromsys.stdinor user-specified file paths. 2. Boundary markers: The skill relies on JSON structural integrity; data is parsed into Python dictionaries and then serialized usingjson.dump, which provides clear syntax-level boundaries. 3. Capability inventory: The skill's capabilities are limited to local file system read/write operations. 4. Sanitization: The skill uses the standard Pythonjsonlibrary, which automatically handles escaping for JSON syntax.
Audit Metadata