microsoft-power-bi
Warn
Audited by Socket on May 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent with its stated Power BI purpose and uses an official same-brand npm CLI, but it routes authentication and API traffic through Membrane rather than directly to Microsoft. That third-party proxy model is proportionate to the product but raises medium data-flow and credential-forwarding risk, especially with broad action execution and an unpinned global CLI install.
Confidence: 84%Severity: 56%
Audit Metadata