m365-copilot-extensions

Warn

Audited by Snyk on Mar 31, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The manifest example includes a connected data URL (https://contoso.sharepoint.com/sites/policies) that Copilot/Graph connectors will fetch at runtime and inject into the model context to ground responses, so external content directly influences agent outputs and is a required runtime dependency.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 31, 2026, 03:10 PM
Issues
1