mpg-sdk-migration
Warn
Audited by Snyk on Mar 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill explicitly reads and uses the public Azure REST API Specs repository (../azure-rest-api-specs / https://github.com/Azure/azure-rest-api-specs) and its TypeSpec files (main.tsp, tspconfig.yaml, commit SHAs) as part of the required generation and autonomous build-fix loop (see the Prerequisites and Phase 1/Phase 6/Phase 8 notes), so untrusted public spec content would be ingested and can directly influence code-generation decisions and automated fixes.
Audit Metadata