powerbi
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill content consists of documentation, architectural diagrams, and code snippets for Power BI, which are for reference and do not contain executable malicious code.
- [SAFE]: The Power Query examples follow security best practices by utilizing a GetSecret function for API authentication instead of hardcoding sensitive credentials.
- [SAFE]: No evidence of obfuscation, hidden URLs, or malicious redirection was found in the provided code or metadata.
- [SAFE]: Evaluation of Category 8 (Indirect Prompt Injection) surface area: 1. Ingestion points: External data enters through PostgreSQL and REST API connections (defined in SKILL.md). 2. Boundary markers: None present. 3. Capability inventory: The skill has access to Read, Write, and Bash tools. 4. Sanitization: Tokens are handled via secure secret retrieval. The surface is used for standard business intelligence tasks with no malicious intent detected.
- [SAFE]: No persistence mechanisms, unauthorized privilege escalation, or remote code execution patterns were identified.
Audit Metadata