azure-ai-transcription-py

Warn

Audited by Snyk on Mar 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's batch and streaming examples in SKILL.md and the acceptance criteria explicitly ingest audio from external URLs via the content_urls parameter (e.g., "https://storage.example.com/audio.wav"), which causes the agent to transcribe and act on untrusted third‑party audio content that could contain instructions influencing its behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 1, 2026, 12:34 AM