power-bi-salespulse-dashboard
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of documentation, DAX formulas, and Power Query snippets designed to help users configure a visualization dashboard.
- [SAFE]: Credentials and configuration secrets are managed securely using placeholders (e.g.,
${POWERBI_ACCESS_TOKEN},${DB_SERVER}) and environment variables (os.environ) in the provided integration templates. - [INDIRECT_PROMPT_INJECTION]: The skill describes a system for processing external retail transaction data, which introduces a potential surface for indirect prompt injection.
- Ingestion points: Local CSV datasets (Global Superstore) and remote SQL database connections defined in Power Query.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the ingested transaction data.
- Capability inventory: The skill includes setup instructions involving file extraction (
unzip), network interaction with the Power BI REST API (requests.post), and database queries. - Sanitization: No explicit validation or sanitization routines are provided for the retail data input streams.
Audit Metadata