power-bi-salespulse-360-dashboard

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download a project repository and dataset from an external GitHub account using the command git clone https://github.com/MahbubNibir/power-bi-retail-analytics-viz.git.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from a CSV file (GlobalSuperstore.csv), which introduces a potential attack surface for indirect prompt injection if the data contains malicious instructions.
  • Ingestion points: The Csv.Document(File.Contents("data/GlobalSuperstore.csv")) function in the Power Query M scripts used for data loading.
  • Boundary markers: None present to distinguish data from instructions within the ingested file.
  • Capability inventory: Data transformation, visualization, and calculation (DAX) within the Power BI Desktop environment.
  • Sanitization: The skill includes basic cleaning steps like trimming whitespace, replacing nulls, and standardizing column names, but lacks specific sanitization for embedded natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — power-bi-salespulse-360-dashboard