microsoft-fabric-unified-analytics

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill demonstrates secure handling of sensitive information by using mssparkutils.credentials.getSecret to retrieve SAS tokens from Key Vault and environment variables for API access tokens, rather than hardcoding them.
  • [COMMAND_EXECUTION]: The provided PySpark and Power Query M code snippets are designed for data engineering tasks within the Fabric environment. These are standard operations for the skill's stated purpose and do not involve arbitrary command execution on the host system.
  • [EXTERNAL_DOWNLOADS]: The skill includes a reference link to an external GitHub repository for project documentation but does not contain any automated instructions to download, install, or execute remote scripts or binaries.
  • [INDIRECT_PROMPT_INJECTION]: While the skill establishes a data pipeline that ingests external CSV files, the processing logic is strictly analytical (aggregation, cleaning) and does not involve passing data content to an LLM as instructions, effectively mitigating injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — microsoft-fabric-unified-analytics