Skip to content

Security: Streamline-Analytics/pbip-agent-stack

SECURITY.md

Security

What this repo is

A public Cursor plugin of mechanical Power BI PBIP / Microsoft Fabric / Amazon Athena agent skills. Rules only. No client deliverables.

What this repo is not

  • Not a report pack, semantic model, or lakehouse dump
  • Not a place for workspace GUIDs, tenant IDs, connection strings, or OAuth tokens
  • Not a vendor of the pstack plugin source

Leak-scan

scripts/leak-scan.sh is the gate. It fails the build on a hashed deny-list of private identifiers (the identifiers themselves are not stored in this repo), plus UUID literals, emails, IPv4 addresses, absolute checkout paths, and secret-shaped tokens.

Run locally before opening a PR:

bash scripts/leak-scan.sh

See docs/leak-policy.md.

Reporting

If you find a leak in a published release, open a private security advisory on the GitHub repo or email the maintainer listed on the profile. Do not file a public issue that repeats the leaked identifier.

There aren't any published security advisories