azure-vm-scalesets
Warn
Audited by Snyk on Mar 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill explicitly requires runtime network fetches of external Markdown via the mcp_microsoftdocs:microsoft_docs_fetch tool (preferred) and the fallback fetch_webpage (e.g., "mcp_microsoftdocs:microsoft_docs_fetch?from=learn-agent-skill" and "fetch_webpage?from=learn-agent-skill&accept=text/markdown"), and that fetched content is injected into the agent context to drive responses, so these runtime URLs can directly control prompts.
Audit Metadata