power-automate-build
Warn
Audited by Snyk on Apr 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly teaches using a no-schema HTTP Request trigger for external webhooks (references/trigger-types.md: "No-Schema Variant (Accept Arbitrary JSON)" citing Stripe/GitHub) and repeatedly shows using triggerBody()/outputs() from those incoming, untrusted webhook or mailbox contents to drive actions (SendEmail, PostMessage, HTTP, etc.), so third-party/user-provided content is ingested and can materially influence behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata