power-bi-salespulse-360-dashboard
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to download a project repository and dataset from an external GitHub account using the command
git clone https://github.com/MahbubNibir/power-bi-retail-analytics-viz.git. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from a CSV file (
GlobalSuperstore.csv), which introduces a potential attack surface for indirect prompt injection if the data contains malicious instructions. - Ingestion points: The
Csv.Document(File.Contents("data/GlobalSuperstore.csv"))function in the Power Query M scripts used for data loading. - Boundary markers: None present to distinguish data from instructions within the ingested file.
- Capability inventory: Data transformation, visualization, and calculation (DAX) within the Power BI Desktop environment.
- Sanitization: The skill includes basic cleaning steps like trimming whitespace, replacing nulls, and standardizing column names, but lacks specific sanitization for embedded natural language instructions.
Audit Metadata