remediate-okta-session-kill

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is designed for security incident response and includes extensive safety controls. It defaults to a dry-run mode that only prints intended actions without executing them.
  • [SAFE]: Execution of remediation actions requires explicit human-in-the-loop parameters, including a mandatory incident ID and approver name via environment variables.
  • [SAFE]: Implements a robust auditing mechanism that dual-writes to Amazon DynamoDB and KMS-encrypted S3 buckets before and after each Okta API call.
  • [SAFE]: Prevents accidental targeting of sensitive or administrative accounts through a built-in deny-list of protected principal patterns.
  • [EXTERNAL_DOWNLOADS]: The skill relies on standard, well-known Python libraries httpx and boto3 for network communications and AWS service interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:18 AM
Security Audit — agent-trust-hub — remediate-okta-session-kill