microsoft-azure-webjobs-extensions-authentication-events-dotnet

Warn

Audited by Snyk on Mar 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's "Token Enrichment with External Data" workflow explicitly fetches and deserializes data from an external API (GetUserProfileAsync calling https://api.example.com/users/{userId}) and uses that data to add/modify token claims, so untrusted third-party content could materially influence behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 1, 2026, 09:02 AM