powerbi-report-authoring

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • Standard Tooling and Dependencies: The skill utilizes official CLI tools (@microsoft/powerbi-report-authoring-cli and @microsoft/powerbi-desktop-bridge-cli) for its operations. These dependencies are installed via standard package managers and originate from the vendor's own ecosystem.
  • Indirect Prompt Injection Surface: As a tool that reads and modifies project files (such as PBIR JSON and TMDL files), there is a theoretical surface for indirect prompt injection if those files contain untrusted content. However, the skill incorporates validation steps (powerbi-report-author validate) and rendered-output review (screenshots) as standard parts of the workflow.
  • Version Control Integration: The inclusion of Git-based version control workflows is a best practice, allowing users to track, review, and revert changes made by the agent, which enhances transparency and control.
  • Data Handling: The skill operates on local project files within the user's workspace. It describes mechanisms for reading and writing these files to achieve the stated goal of report authoring, with no evidence of unauthorized data exfiltration or credential harvesting.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 02:44 PM
Security Audit — agent-trust-hub — powerbi-report-authoring