Atlas / MCP servers / sulaiman013 / Power BI

Power BISAFE

mcp/sulaiman013/power-bi-1

MCP server for natural language interaction with Power BI datasets

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
74 46r · 25w · 3d
Transport
stdio
License
MIT
Stars
123
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An enterprise-grade Model Context Protocol server for Power BI and Microsoft Fabric.

Let AI assistants inspect, query, validate, optimize, govern, and safely refactor Power BI semantic models and reports, through natural language.

Disclaimer: This is an independent, community project. It is not affiliated with, endorsed by, or connected to Microsoft Corporation or Anthropic.

What it is

Power BI MCP Server connects an AI assistant (Claude, GitHub Copilot, any MCP client) to your Power BI content through one consistent interface. It talks to a local Power BI Desktop model (queries AND live writes), a published Power BI Service dataset, Power BI Project (PBIP) files on disk, and the running Power BI Desktop app itself (through Microsoft's Desktop Bridge, for hot-reload and screenshots), and wraps every operation in a security and governance layer.

It exposes 82 tools plus MCP resources, prompts, and completion, and ships with 25 assert-based test suites.

Read from source at commit 200d247c8351OBSERVED · 2026-10-07
02

Exposed tools (74)

46 read · 25 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_model_storagereadVertiPaq-style storage analysis: per-table row counts (exact via DAX COUNTROWS), column counts, and best-effort sizes, ranked to find the biggest/most expensive tables for optimization.
analyze_query_performancewriteExecute a DAX query and report duration, row count, and heuristic optimization hints. For storage-engine vs formula-engine server timings use DAX Studio.
audit_ai_readinessreadScore how AI-ready (Copilot/agent-ready) the model is: coverage of descriptions and format strings on measures, columns, and tables. Returns a 0-100 score, metrics, and concrete recommendations.
audit_namingreadAudit naming conventions across the connected model
batch_create_measureswriteCreate MANY measures on a table of the connected Power BI Desktop model in one all-or-nothing batch (TOM). The whole batch is pre-validated (each expression probed against the live model, duplicate names rejected) before anything is created. Honors an open tom transaction.
batch_rename_columnswrite⚠️ DEPRECATED: Use
batch_rename_measureswrite⚠️ DEPRECATED: Use
batch_rename_tableswrite⚠️ DEPRECATED: Use
batch_update_measureswriteBulk update multiple measure expressions in the Power BI Desktop model.
bpa_audit_rule_sourcesreadAudit where BPA rules live for the loaded PBIP project: rules embedded in the model (BestPracticeAnalyzer annotation), external rule-file URLs, and ignored rule IDs, merged with any local user/machine BPARules.json found. Reveals shadow governance and ignored rules.
bridge_manifestreadReturn the Desktop Bridge method manifest for a running Power BI Desktop process: which bridge methods this Desktop build supports, with their descriptions. Use to discover capabilities before calling them (the bridge surface is preview and grows over time).
bridge_screenshotreadCapture PNG screenshots of report pages from the RUNNING Power BI Desktop via the Desktop Bridge - the agent can literally see the rendered report. Pass a page id or display name, or
create_measurewriteCreate a new DAX measure in the Power BI Desktop model.
create_relationshipwriteCreate a relationship between two columns in the connected Power BI Desktop model (TOM). Honors an open tom transaction.
dax_lintreadStatic-analyze DAX for performance anti-patterns and correctness traps (FILTER over a whole table in CALCULATE, nested CALCULATE,
dax_suggest_rewritereadFor the auto-fixable DAX anti-patterns (bare
delete_measuredestructiveDelete a measure from the Power BI Desktop model.
delete_relationshipdestructiveDelete a relationship in the connected Power BI Desktop model (TOM), identified by name or by from/to table (and optionally column). Honors an open tom transaction.
desktop_connectreadConnect to a Power BI Desktop instance by port number. Optionally specify an RLS role to test.
desktop_discover_instancesreadDiscover all running Power BI Desktop instances on this machine
desktop_execute_daxwriteExecute a DAX query against the connected Power BI Desktop model
desktop_get_model_inforeadGet comprehensive model info (tables, columns, measures, relationships) from Power BI Desktop
desktop_list_columnsreadList columns for a table in the connected Power BI Desktop model
desktop_list_measuresreadList all measures in the connected Power BI Desktop model
desktop_list_rls_rolesreadList all RLS (Row-Level Security) roles defined in the Power BI Desktop model
desktop_list_tablesreadList all tables in the connected Power BI Desktop model
desktop_rls_statusreadGet the current RLS status including active role and available roles
desktop_set_rls_roledestructiveSet or clear the active RLS role for testing. When set, all queries will be filtered by that role
execute_daxwriteExecute a DAX query against a Power BI Service dataset
export_data_dictionaryreadGenerate a portable data dictionary (tables, columns, measures with DAX, relationships) for the connected model, with a documentation-coverage score. Returns Markdown or HTML; optionally writes to a file. Re-runnable in CI so docs never go stale.
find_unused_objectsreadFind columns and measures not referenced by any other model object (INFO.CALCDEPENDENCY), relationship, or - when a PBIP project is loaded - any report visual. Safe-cleanup candidate list (a free replacement for paid unused-object tools).
fleet_refresh_monitorreadRefresh health across many datasets: for each refreshable dataset in the given workspaces, check the most recent refresh and classify failures (root cause). Centralized
generate_svg_measurereadGenerate a ready-to-use DAX measure that returns an inline SVG micro-visual (progress bar, bullet chart, status pill, or sparkline) as a data:image/svg+xml URI. Set the measure
get_model_inforeadGet comprehensive model info from a Power BI Service dataset using INFO.VIEW functions
impact_analysisreadBlast radius before a change: lists model objects that depend on a measure/column (INFO.CALCDEPENDENCY) and, when a PBIP project is loaded, the report files/visuals that reference it. Run before renaming or deleting.
list_columnsreadList columns for a table in a Power BI Service dataset
list_datasetsreadList all datasets in a Power BI Service workspace
list_tablesreadList all tables in a Power BI Service dataset via XMLA
list_workspacesreadList all Power BI Service workspaces accessible to the Service Principal
model_diffreadProduce a human-readable semantic diff (added/removed/changed tables, columns, measures, relationships) between a baseline snapshot and either another snapshot or the live model. Ideal for PR review and pre-deploy
model_snapshotreadCapture the connected model
pbip_add_hierarchywriteAdd a drill-down hierarchy to a table OFFLINE in the loaded PBIP project (TMDL), e.g. Year > Quarter > Month > Date or Category > Subcategory > Product. Levels are existing columns of the table (validated first).
pbip_add_measureswriteBulk-add measures OFFLINE into a loaded PBIP project
pbip_create_date_tablewriteCreate a complete DAX date-dimension table OFFLINE in the loaded PBIP project: a calculated table over CALENDAR() with Year/Quarter/Month/Month Number/Week/Day columns, marked as the model
pbip_fix_broken_visualswriteFix broken visual references after a table rename. Use this when TOM/API renamed a table but visuals still reference the old name. Supports both PBIR-Legacy and PBIR-Enhanced formats.
pbip_fix_dax_quotingreadFix all DAX expressions by properly quoting table names with spaces. Fixes: Leads Sales Data[Amount] ->
pbip_get_project_inforeadGet information about the loaded PBIP project including paths to TMDL files and report.json
pbip_load_projectreadLoad a PBIP (Power BI Project) for file-based editing. PBIP format allows safe bulk renames without breaking report visuals. Use
pbip_rename_columnswrite✅ RECOMMENDED: Safely rename columns in a PBIP project. Updates TMDL files, DAX references, and report visuals. Close Power BI Desktop first, then reopen after.
pbip_rename_measureswrite✅ RECOMMENDED: Safely rename measures in a PBIP project. Updates TMDL files, DAX references, and report visuals. Close Power BI Desktop first, then reopen after.
pbip_rename_tableswrite✅ RECOMMENDED: Safely rename tables in a PBIP project. Updates EVERYTHING: TMDL files, DAX references (with proper quoting), report visuals, and Q&A schema. Close Power BI Desktop first, then reopen after.
pbip_scan_broken_refsreadScan the PBIP project for broken references. Compares table names in semantic model vs report visuals to find mismatches.
pbip_validatereadValidate TMDL syntax in the loaded PBIP project. Checks for unquoted names with spaces, invalid references, etc.
pbir_add_pagewrite[PREVIEW] Add a new report page to the loaded PBIR-Enhanced PBIP project. Writes a schema-valid page.json and registers it in pages.json. Close Power BI Desktop before editing; reopen after.
pbir_add_visualwrite[PREVIEW] Add a visual to a page in the loaded PBIR-Enhanced project. Supported visual_type: card, kpi, tableEx, slicer, barChart, columnChart, lineChart, areaChart, pieChart, donutChart, gauge, pivotTable.
pbir_bind_fieldswrite[PREVIEW] Add or replace field bindings on an existing visual without recreating it. mode
pbir_validate_reportread[PREVIEW] Validate that every field referenced by the report
pbix_extractreadExtract a .pbix package to a folder (Zip-Slip protected). Also decodes the legacy UTF-16-LE Report/Layout into a readable UTF-8 Report/Layout.json so an agent can inspect or edit the report structure. Returns the list of extracted files.
pbix_inspectreadInspect a .pbix file (an OPC ZIP package) without extracting: classify it as thick (imported model) vs thin (live connection), detect the report format (legacy Report/Layout vs PBIR), count pages, and list every internal entry with size. The first step to working with a real .pbix.
pre_deploy_gatewriteCI/pre-deploy quality gate: runs the Best Practice Analyzer and AI-readiness audit and returns a machine PASS/FAIL verdict with blocking issues. Fails on any BPA error (and optionally warnings) or AI score below min_ai_score.
refresh_doctorreadDiagnose a dataset
rls_test_harnessreadEvaluate a measure or table row count under EVERY RLS role and return a pass/fail matrix vs the unrestricted baseline, flagging roles that see everything (no filtering) or nothing. Tests row-level security systematically on the connected Desktop model. Always restores the cleared role afterward.
run_bpawriteRun a Best Practice Analyzer over the connected semantic model (performance, DAX, naming, formatting, maintenance, error-prevention rules). Returns findings with severity, the offending object, and a fix hint.
run_dax_testswriteRun a suite of DAX regression tests against the model: each test is {name, dax, expected, tolerance?}; returns PASS/FAIL per test and an overall verdict. Use to catch measure regressions before deploy. Provide tests inline or via tests_path (JSON file).
scan_measure_dependenciesreadAnalyze the dependency graph of a measure or column using INFO.CALCDEPENDENCY: upstream (what it depends on) and downstream (what depends on it). Use before renaming or deleting to see what would break.
scan_referential_integrityreadScan every active relationship for referential-integrity violations: fact keys with no matching dimension row (the cause of the hidden blank row and silently wrong totals). Runs an EXCEPT count per relationship against the connected model and reports orphan-key counts with samples.
scan_table_dependenciesreadScan a table to find all references before renaming. Shows measures, calculated columns, and relationships that depend on this table. IMPORTANT: Use this before batch_rename_tables to understand the impact.
security_audit_logreadView recent entries from the security audit log
security_statusreadGet the current security settings and status (PII detection, audit logging, access policies)
tom_begin_transactionwriteBegin a TOM write transaction. While open, model write tools (create_measure, delete_measure, batch_update_measures) defer saving until tom_commit_transaction, so a batch of edits is atomic and can be rolled back.
tom_commit_transactionwriteCommit (SaveChanges) all pending TOM model edits made since tom_begin_transaction and close the transaction.
tom_rollback_transactionreadRoll back (UndoLocalChanges) all pending TOM model edits made since tom_begin_transaction and close the transaction.
usage_and_orphan_analyticsreadTenant usage analytics from the Admin Activity Events API for one UTC day: total events, distinct users, top activities, top viewed reports, top users. Requires Fabric admin (28-day retention). Defaults to yesterday (today is incomplete).
validate_daxreadValidate a DAX query or scalar measure expression against the connected model WITHOUT committing anything. Executes a minimal probe and returns syntax/semantic errors so an agent can self-correct before writing a measure.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_measure, delete_relationship, desktop_set_rls_role
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/server.py:4257
data = base64.b64decode(snap.get("payload") or "")
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/test_phase3_rename_safety.py:31
p.write_bytes("table Sales\r\n\tcolumn Amount\r\n".encode("utf-8"))
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/test_phase3_rename_safety.py:33
check("BOM stripped from text", not text.startswith(""))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, msal, requests, python-dotenv, psutil, pythonnet, pyadomd, pyyaml
Why it matters. 8 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 200d247c8351full audit observations/trust-audit/mcp-server/sulaiman013__power-bi-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07200d247c8351SAFEB89first audit
05

Questions

What is the Power BI MCP server?

MCP server for natural language interaction with Power BI datasets

What tools does Power BI expose?

74 in total: 46 read-only, 25 that write, and 3 that can delete or overwrite (delete_measure, delete_relationship, desktop_set_rls_role). Every one is listed on this page with its risk.

Is Power BI safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Power BI need?

It reads CLIENT_SECRET and POWERBI_MCP_AUDIT_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Power BI run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (200d247c8351), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement