powerbi-documentation

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from user-uploaded files to enrich documentation context. \n- Ingestion points: The agent reads user-uploaded files (e.g., requirements, data dictionaries) from /mnt/user-data/uploads/. \n- Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded commands in the uploaded content. \n- Capability inventory: The skill uses docx generation, Mermaid diagram creation, and a suite of Power BI metadata extraction tools via the powerbi-modeling-mcp server. \n- Sanitization: No sanitization or filtering is applied to the extracted context before its use in generating summaries and recommendations. \n- [CREDENTIALS_UNSAFE]: The skill documents data source connection strings and Power Query M code snippets, which are high-value targets for credential exposure. \n- Evidence: The skill instructs the agent to extract and display these details, relying on the agent's ability to 'REDACT sensitive credentials' and 'REDACT sensitive values' manually, which presents a risk of accidental exposure if the agent fails to identify specific secret patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 05:51 PM
Security Audit — agent-trust-hub — powerbi-documentation