onelake-catalog-govern-cli

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • Comprehensive Governance Framework: The skill provides a highly structured and safe approach to managing Microsoft Fabric resources. It emphasizes a 'Must/Prefer/Avoid' philosophy that aligns with security best practices.
  • Safety Gates for Irreversible Operations: The skill explicitly defines 'MUST-DO' gates for terminal actions like deleting domains or bulk sensitivity label changes, requiring explicit user confirmation and dry-runs.
  • Least Privilege and RBAC Awareness: It correctly distinguishes between Fabric Tenant Admin, Domain Admin, and Workspace Admin roles, ensuring the agent uses the appropriate API tier and informs the user when permissions are insufficient.
  • Validated Data Sources: The skill uses official Microsoft Fabric, Power BI, and Graph API endpoints, providing clear documentation on data lag and blind spots to prevent misleading reports.
  • Sanitization and Review: Instructions caution against auto-generating descriptions or executing bulk changes without human review, mitigating risks associated with automated management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 01:44 PM
Security Audit — agent-trust-hub — onelake-catalog-govern-cli