convert-ocsf-to-sarif

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates entirely locally to perform data transformation and contains no network-reaching code or external dependencies. It is authored by 'msaad00' and correctly references the vendor's own repository at 'github.com/msaad00/cloud-ai-security-skills' for tool information.
  • [COMMAND_EXECUTION]: The script src/convert.py implements a command-line interface using argparse that allows reading from and writing to arbitrary file paths provided by the user. This functionality is consistent with the skill's intended purpose as a conversion utility for security logs.
  • [PROMPT_INJECTION]: The skill processes untrusted OCSF JSONL logs, creating a surface for indirect prompt injection. Since the skill maps this data into a structured SARIF format for display in external security dashboards, the potential impact is restricted to deceptive content in those viewers, with no mechanism for execution within the skill itself. 1. Ingestion points: src/convert.py (line 217) reads log data from sys.stdin or user-specified file paths. 2. Boundary markers: The skill relies on JSON structural integrity; data is parsed into Python dictionaries and then serialized using json.dump, which provides clear syntax-level boundaries. 3. Capability inventory: The skill's capabilities are limited to local file system read/write operations. 4. Sanitization: The skill uses the standard Python json library, which automatically handles escaping for JSON syntax.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:18 AM
Security Audit — agent-trust-hub — convert-ocsf-to-sarif