powerbi-mcp
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill implements a robust safety protocol for Power BI data modeling, prioritizing human-in-the-loop confirmation for all structural and destructive changes.
- [PROMPT_INJECTION]: The skill identifies and defends against indirect prompt injection by explicitly instructing the agent to ignore and report instructions embedded in untrusted model metadata such as table names or TMDL descriptions (SKILL.md). Ingestion points include Power BI model data; boundary markers are established via Tier-based confirmations; capabilities include model mutation via MCP tools; and sanitization is enforced through explicit defensive instructions.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation and public repositories from trusted organizations including Microsoft and the Agent Skills community for informational purposes (SKILL.md, local.patch).
Audit Metadata