spmi-auditee
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill enforces strong security boundaries by requiring role validation and tenant-scoping before any operations are performed.
- [SAFE]: It contains explicit prohibitions against requesting, storing, or revealing authentication tokens, effectively preventing credential exposure.
- [SAFE]: The implementation of least privilege is evident as it restricts the available tools to only those required for the 'auditee' role and forbids the use of administrative or auditing tools.
- [SAFE]: A human-in-the-loop requirement is enforced, necessitating explicit user approval before any document submission occurs.
Audit Metadata