ingest-mcp-proxy-ocsf
Installation
SKILL.md
ingest-mcp-proxy-ocsf
Thin, single-purpose ingestion skill: raw MCP proxy JSONL in → OCSF 1.8 Application Activity JSONL by default, or the repo-owned native application-activity projection when requested. No detection logic, no side effects, no external calls.
Wire contract
Reads the format emitted by the agent-bom proxy command:
{
"timestamp": "2026-04-10T05:00:00.000Z",
"session_id": "sess-abc",
"method": "tools/list",
"direction": "response",
"body": { "tools": [ ... ] }
}
Writes OCSF 1.8 Application Activity (class 6002) with the cloud_security_mcp custom profile. See ../OCSF_CONTRACT.md for the field-level pinning.