m365-copilot-extensions
Warn
Audited by Snyk on Mar 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The manifest example includes a connected data URL (https://contoso.sharepoint.com/sites/policies) that Copilot/Graph connectors will fetch at runtime and inject into the model context to ground responses, so external content directly influences agent outputs and is a required runtime dependency.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata