power-bi-retail-analytics-salespulse360
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a project repository from an external GitHub account (
github.com/MahbubNibir/power-bi-retail-analytics-viz.git). While this is central to the skill's functionality, the source is an individual developer rather than a verified organization. - [INDIRECT_PROMPT_INJECTION]: The skill processes the Global Superstore retail dataset and provides scripts for data export and network communication. This environment constitutes an indirect prompt injection surface if the input data were to contain malicious instructions, as the skill does not specify boundary markers or sanitization procedures for the ingested CSV data.
- Ingestion points:
global_superstore.csv(referenced in SKILL.md). - Boundary markers: None identified in the provided instructions.
- Capability inventory: Includes repository cloning, CSV extraction, PowerShell process execution, Python-based file exports, and Node.js-based network requests (
axios.post). - Sanitization: No explicit sanitization or validation logic is provided for the input data streams.
Audit Metadata