ingest-gcp-scc-ocsf
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a stateless data processor that converts JSON-formatted security findings between schemas. It does not perform any network communication or external data exfiltration.
- [SAFE]: Analysis of the Python source code confirms that it relies entirely on the Python standard library (argparse, hashlib, json, re, etc.) and does not require or install any third-party or untrusted dependencies.
- [SAFE]: There is no evidence of prompt injection, obfuscation, or dynamic execution of untrusted code. The logic focuses on timestamp parsing, field mapping, and JSON serialization.
- [SAFE]: The skill does not access sensitive system files or environment variables. It processes input provided via stdin or a specified file and outputs results to stdout or a file.
- [SAFE]: No hidden instructions or deceptive metadata were found in the skill manifest or documentation.
Audit Metadata