ingest-cloudtrail-ocsf
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a deterministic transformation logic for mapping AWS CloudTrail event fields to the Open Cybersecurity Framework (OCSF) API Activity class.
- [SAFE]: No network operations (such as HTTP requests or socket connections) are present in the code, precluding data exfiltration risks.
- [SAFE]: The script uses standard library modules (json, argparse, hashlib) to handle data and does not employ dynamic code execution (eval/exec) or remote script downloads.
- [SAFE]: File system interaction is strictly limited to reading input logs and writing transformed output as directed by command-line arguments or standard streams.
- [SAFE]: No hardcoded credentials or sensitive environment variable access were found in the codebase.
Audit Metadata