pbir-cli

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated Power BI report purpose, but it depends on an external `pbir` CLI whose provenance is only partly reassuring: same-repo/PyPI distribution is normal, yet proprietary-binary indications plus unsigned installer guidance elevate supply-chain risk. No clear credential theft or mismatched data routing is evident, so this is not malicious, but the install/execution trust profile is high enough to treat as risky.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
May 14, 2026, 12:46 PM
Package URL
pkg:socket/skills-sh/data-goblin%2Fpower-bi-agentic-development%2Fpbir-cli%2F@1b91ba5d102ffee0fedcb9f7be8e913eaedcc88a
Security Audit — socket — pbir-cli