Skip to main content
Manusで任意のスキルを実行
ワンクリックで

ingest-mcp-proxy-ocsf

スター3
フォーク0
更新日2026年7月10日 03:53

Convert raw MCP proxy logs (from agent-bom proxy or any MCP JSON-RPC middleware) into Application Activity records. OCSF 1.8 (class 6002) is the default output, with a native projection available via `--output-format native`. Every event carries session_uid, JSON-RPC method, direction, and a stable tool fingerprint (sha256 of name + description + inputSchema + annotations) so downstream detection skills can spot schema drift. Use when the user mentions MCP proxy logs, OCSF ingestion, detection engineering pipeline, or wants to feed MCP traffic into a SIEM or detection stack. Do NOT use for CloudTrail, GCP audit, Azure Activity, or K8s audit logs (use ingest-cloudtrail-ocsf / ingest-gcp-audit-ocsf / ingest-azure-activity-ocsf / ingest-k8s-audit-ocsf respectively). Do NOT use as a detection skill — this skill only normalises, it does not flag anything.

インストール

Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。

ファイルエクスプローラー
6 ファイル
SKILL.md
readonly