remediate-okta-session-kill
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill is designed for security incident response and includes extensive safety controls. It defaults to a dry-run mode that only prints intended actions without executing them.
- [SAFE]: Execution of remediation actions requires explicit human-in-the-loop parameters, including a mandatory incident ID and approver name via environment variables.
- [SAFE]: Implements a robust auditing mechanism that dual-writes to Amazon DynamoDB and KMS-encrypted S3 buckets before and after each Okta API call.
- [SAFE]: Prevents accidental targeting of sensitive or administrative accounts through a built-in deny-list of protected principal patterns.
- [EXTERNAL_DOWNLOADS]: The skill relies on standard, well-known Python libraries
httpxandboto3for network communications and AWS service interactions.
Audit Metadata