ingest-gcp-audit-ocsf

Installation
SKILL.md

ingest-gcp-audit-ocsf

Thin, single-purpose ingestion skill: raw GCP Cloud Audit Logs in -> canonical API activity projection -> OCSF 1.8 API Activity JSONL or native enriched API activity JSONL out. No detection logic, no GCP API calls, no side effects.

Wire contract

GCP Cloud Audit Logs use the google.cloud.audit.AuditLog protobuf, exported to Cloud Logging and from there to BigQuery, Pub/Sub, or Cloud Storage. The skill reads the JSON serialisation:

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
ingest-gcp-audit-ocsf — msaad00/cloud-ai-security-skills