powerbi-modeling
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes Power BI model metadata via MCP tools which constitutes an untrusted data ingestion surface.
- Ingestion points: Data retrieved from Power BI models via MCP tools (e.g., table_operations) in SKILL.md and scripts/powerbi-model-audit.py.
- Boundary markers: The skill lacks explicit delimiters or instructions for the agent to ignore potentially malicious content embedded in model metadata.
- Capability inventory: The skill utilizes MCP tools capable of creating and updating model components (measure_operations, table_operations, security_role_operations).
- Sanitization: No explicit sanitization or validation logic for model metadata is present in the provided instructions or scripts.
Audit Metadata