Getting it into your agent
There is no command for this one: it runs only inside a plugin, and the catalogue could not identify which plugin ships it. The source is linked below.
Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/santoshkanthety/powerbi-agent/powerbi-audit-tenant-settings)<a href="https://agentmods.dev/skills/santoshkanthety/powerbi-agent/powerbi-audit-tenant-settings"><img src="https://agentmods.dev/badge/skills/santoshkanthety/powerbi-agent/powerbi-audit-tenant-settings/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/santoshkanthety/powerbi-agent/powerbi-audit-tenant-settings"><img src="https://agentmods.dev/badge/skills/santoshkanthety/powerbi-agent/powerbi-audit-tenant-settings.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00043 | $0.04179 |
| Opus 5 | $0.00022 | $0.02090 |
| Sonnet 5 | $0.00009 | $0.00836 |
| Haiku 4.5 | $0.00004 | $0.00418 |
Grade A, and why
powerbi-audit-tenant-settings scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 228 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Audit Tenant Settings
Audit Fabric / Power BI tenant settings against a curated baseline, surface drift, enumerate delegated overrides at capacity / domain / workspace scope, investigate the Entra security groups those settings reference, and turn findings into a grounded discussion about what to do next. Always invoke the fabric-cli skill alongside this skill; it provides the fab CLI guidance, admin API references, and the microsoft-learn MCP server that this skill depends on.
Prerequisites
This plugin is an add-on to the fabric-cli plugin. It requires:
- fabric-cli plugin installed and enabled; provides
fabCLI guidance, themicrosoft-learnMCP server, and admin API reference docs. - fab CLI (
ms-fabric-cli) authenticated with a Fabric / Power BI admin account. - az CLI authenticated with Graph permissions (
Group.Read.All,User.Read.All,Directory.Read.All,RoleManagement.Read.Directory) when investigating security groups.
Settings
Per-project configuration via .claude/fabric-admin.local.md:
---
enabled: true
tenant_label: "Contoso"
snapshot_path: "~/.cache/fabric-admin-audit/last-snapshot.json"
drift_threshold_high: 5
drift_threshold_medium: 15
notification_level: "info"
schedule: "weekly"
---
# Fabric Admin Configuration
Additional context or tenant-specific notes.
| Field | Type | Default | Purpose |
|---|---|---|---|
enabled |
bool | true |
Toggle the plugin on/off |
tenant_label |
string | none | Label for PDF masthead and audit reports |
snapshot_path |
string | ~/.cache/fabric-admin-audit/last-snapshot.json |
Where to store/read the last-run snapshot JSON |
drift_threshold_high |
int | 5 |
Alert when high-risk drift count exceeds this |
drift_threshold_medium |
int | 15 |
Alert when total drift count exceeds this |
notification_level |
string | info |
Verbosity: quiet, info, verbose |
schedule |
string | weekly |
Preferred audit cadence: daily, weekly, monthly, ad-hoc |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 228 lines · 43 tokens per session scan A c6d8398b5250
powerbi-audit-tenant-settings is a skill published in the GitHub repository santoshkanthety/powerbi-agent (2 stars, last pushed 13d ago), licensed MIT. It adds 43 tokens to every session and 4,179 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
seshat-bi
Route a BI project through Seshat BI's governed seven-stage readiness flow. Use when a user asks to inspect a retail source, initialize a Seshat project, find the truthful next action, validate readiness evidence, or stop at the correct human approval gate.
Data Retention Schedule Review
Use when reviewing a draft or existing data retention schedule to inventory data categories against stated purposes, collect retention-period facts, flag legal-hold interactions, and surface orphaned-data and vendor-coverage gaps for attorney review.
powerbi-workflows
Route guarded Power BI work -- design, native report authoring, semantic-model operations, published queries, QA, bounded formatting, and PBIP adoption -- to the correct Seshat or official Microsoft surface under Seshat BI's gates.
dbt-workflows
Route dbt intent to Seshat's governed shadow workflow or the official dbt Labs competence and execution owner, without bypassing readiness or evidence.
dagster-workflows
Route Dagster intent to Seshat's governed medallion workflow or the official Dagster competence owner without bypassing readiness, approvals, or evidence.
pbi-mcp-doctor
Use when a user asks whether or how to wire Microsoft's official Power BI MCP servers into a Seshat BI workspace: run the read-only environment doctor, map a task to the governed Power BI surface (including the official report-authoring skill), generate a safe read-only config template, or run the mocked read-only…