pbir-cli

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated Power BI purpose and does not show clear credential theft or mismatched data exfiltration, but its core dependency is an unverifiable proprietary `pbir` binary. That mandatory black-box CLI, plus transitive fallback to another skill and optional external publishing, makes the skill high risk even without evidence of confirmed malware.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 25, 2026, 01:37 AM
Package URL
pkg:socket/skills-sh/data-goblin%2Fpower-bi-agentic-development%2Fpbir-cli%2F@7f08cb609c03e4b6cae1779c305eb8f87583ef96