spmi-rektorat
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill enforces a read-only architecture by restricting the agent to a specific set of data-retrieval tools and explicitly forbidding any actions related to document submission, validation, or modification.
- [SAFE]: It implements mandatory role-based access control (RBAC), requiring the agent to verify that the 'rektorat' role is active in the authenticated context before proceeding with any tasks.
- [SAFE]: The instructions contain clear security guardrails against credential exfiltration, specifically instructing the agent to never decode, print, or forward authentication tokens in chat interactions.
- [SAFE]: Data isolation is maintained by limiting the agent's scope to authorized tenant IDs (campus_ids) provided by the server, preventing unauthorized data aggregation across campuses.
Audit Metadata