ingest-guardduty-ocsf

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a passthrough ingestion tool, converting structured JSON data from AWS GuardDuty to OCSF format using only Python standard libraries (json, hashlib, datetime, argparse).
  • [DATA_EXFILTRATION]: No unauthorized network operations or hardcoded credentials were detected. Data handling is confined to standard input/output streams or local files specified by the user.
  • [COMMAND_EXECUTION]: The code does not use subprocesses, shell commands, or dynamic execution primitives like exec() or eval().
  • [SAFE]: (Indirect Prompt Injection Surface) While the skill ingests untrusted data from GuardDuty finding fields (title, description) via stdin or files, it lacks exploitable capabilities. The tool's scope is restricted to local data transformation, and it employs standard JSON parsing for sanitization.
  • [REMOTE_CODE_EXECUTION]: No external scripts are fetched or executed at runtime. All dependencies are handled via the environment's standard library.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — ingest-guardduty-ocsf