ingest-gcp-scc-ocsf

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a stateless data processor that converts JSON-formatted security findings between schemas. It does not perform any network communication or external data exfiltration.
  • [SAFE]: Analysis of the Python source code confirms that it relies entirely on the Python standard library (argparse, hashlib, json, re, etc.) and does not require or install any third-party or untrusted dependencies.
  • [SAFE]: There is no evidence of prompt injection, obfuscation, or dynamic execution of untrusted code. The logic focuses on timestamp parsing, field mapping, and JSON serialization.
  • [SAFE]: The skill does not access sensitive system files or environment variables. It processes input provided via stdin or a specified file and outputs results to stdout or a file.
  • [SAFE]: No hidden instructions or deceptive metadata were found in the skill manifest or documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — ingest-gcp-scc-ocsf