powerbi-documentation
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from user-uploaded files to enrich documentation context. \n- Ingestion points: The agent reads user-uploaded files (e.g., requirements, data dictionaries) from
/mnt/user-data/uploads/. \n- Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded commands in the uploaded content. \n- Capability inventory: The skill usesdocxgeneration, Mermaid diagram creation, and a suite of Power BI metadata extraction tools via thepowerbi-modeling-mcpserver. \n- Sanitization: No sanitization or filtering is applied to the extracted context before its use in generating summaries and recommendations. \n- [CREDENTIALS_UNSAFE]: The skill documents data source connection strings and Power Query M code snippets, which are high-value targets for credential exposure. \n- Evidence: The skill instructs the agent to extract and display these details, relying on the agent's ability to 'REDACT sensitive credentials' and 'REDACT sensitive values' manually, which presents a risk of accidental exposure if the agent fails to identify specific secret patterns.
Audit Metadata