power-bi-salespulse-dashboard

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of documentation, DAX formulas, and Power Query snippets designed to help users configure a visualization dashboard.
  • [SAFE]: Credentials and configuration secrets are managed securely using placeholders (e.g., ${POWERBI_ACCESS_TOKEN}, ${DB_SERVER}) and environment variables (os.environ) in the provided integration templates.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a system for processing external retail transaction data, which introduces a potential surface for indirect prompt injection.
  • Ingestion points: Local CSV datasets (Global Superstore) and remote SQL database connections defined in Power Query.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the ingested transaction data.
  • Capability inventory: The skill includes setup instructions involving file extraction (unzip), network interaction with the Power BI REST API (requests.post), and database queries.
  • Sanitization: No explicit validation or sanitization routines are provided for the retail data input streams.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — power-bi-salespulse-dashboard