Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/plugin/plugins/rayfin/plugin.json
Original file line number Diff line number Diff line change
Expand Up @@ -15,5 +15,8 @@
"fabric",
"typescript"
],
"skills": ["skills/rayfin-getting-started"]
"skills": [
"skills/rayfin-getting-started",
"skills/security-best-practices"
]
}
Original file line number Diff line number Diff line change
Expand Up @@ -74,3 +74,18 @@ loading the in-project skill: `create-rayfin` creates a child project directory
`--project-name`, slugified), so `cd` into it; an in-place `rayfin init` scaffolds in the
current directory, so you're already there. Once at the project root, load its
`.agents/skills/rayfin/SKILL.md`.

## Security best practices

Build security into the app from the start:

- Request only the Fabric data and connector permissions the app needs.
- Filter sensitive data server-side and return only the rows and columns required by the UI.
- Keep secrets, tokens, and environment-specific identifiers out of client code, URLs, and logs.
- Avoid rendering PII or detailed errors in the browser unless the user is authorized to see them.
- Remove debug output and verify production configuration before deployment.

Before deployment, run the
[Fabric App Security Review](../security-best-practices/SKILL.md) skill to
check for sensitive data exposure, semantic model risks, unsafe configuration, excessive
permissions, and information leakage.
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
---
name: fabric-app-security-review
description: Review a Fabric App for sensitive data exposure, semantic model security issues, connector risks, and deployment readiness.
---

# Fabric App Security Review

When invoked, perform a security review of the target Fabric App codebase. Focus on whether the app exposes sensitive data to the browser, logs private information, over-fetches from Fabric items, or hardcodes environment-specific configuration.

## Review Steps

1. Review semantic model usage for full-table reads, raw transaction access, unfiltered queries, excessive columns, or queries that return more data than the UI requires.
2. Review React or frontend UI code for PII rendered in the DOM, sensitive props passed between components, or restricted data hidden only with client-side logic.
3. Review API calls for tokens, secrets, workspace IDs, item IDs, tenant IDs, or sensitive query parameters in URLs, request bodies, or logs.
4. Review configuration files such as .env files, manifest.json, app settings, deployment files, and environment configs for hardcoded secrets or identifiers.
5. Review logging and error handling for console.log, console.debug, verbose error objects, stack traces, and debug-only pages that could leak sensitive information.
6. Review connector and Fabric item usage for broad permissions, unnecessary metadata exposure, or environment-specific values that should be resolved securely at runtime.

## Focus Areas

- PII exposure: names, emails, phone numbers, employee data, customer identifiers, salary, financial, or account data.
- Excessive semantic model access: full table retrieval, SELECT-style patterns, raw rows, or large dimensions when measures or aggregates are safer.
- Workspace, item, and tenant ID exposure: identifiers visible in client bundles, URLs, logs, or error messages.
- Client-side filtering: fetching all records and filtering in the browser instead of enforcing least privilege before data reaches the client.
- Debug artifacts: console output, stack traces, temporary debug UI, or commented code that exposes implementation details.

## Output Format

Return findings grouped by Critical, High, Medium, and Low severity. For each finding, include location, issue, why it matters, evidence, recommended fix, and suggested Copilot prompt to remediate it.

## Remediation Guidance

Do not only describe the problem. Recommend a concrete fix, such as moving the filtering server-side, replacing raw data with curated measures, removing logs, moving configuration out of client code, narrowing connector scopes, or using safe error messages.