power-bi
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool for standard development tasks, including Git operations and Azure CLI authentication (
az login). These commands are used as intended for managing project versions and authenticating with official Azure billing services. - [EXTERNAL_DOWNLOADS]: The skill incorporates external information from trusted sources, specifically official Microsoft Learn documentation and Azure SDK references, to provide up-to-date guidance on DAX and Power Query syntax.
- [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes data from external CSV files and Power BI Service pages.
- Ingestion points: Reading Azure Advisor recommendation CSVs and browser-based inspection of Power BI Service refresh history.
- Boundary markers: Boundary markers or specific instructions to ignore embedded commands in the ingested data are not explicitly defined in the templates.
- Capability inventory: The skill has access to subprocess execution (Bash), network operations (Browser tools), and file system writes (Write tool).
- Sanitization: The skill implements schema validation through explicit Power Query type conversions and structured TMDL definitions.
- [SAFE]: The skill demonstrates best practices for handling connector authentication, explicitly warning users that standard Azure RBAC roles are insufficient for the EA connector and providing correct procedures for role assignment in the EA Portal.
Audit Metadata