implementing-scim-provisioning

Warn

Audited by Snyk on Apr 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill explicitly ingests and acts on external, potentially untrusted data from Scalekit's Directory API (Step 4: listDirectoryUsers/listDirectoryGroups) and real-time webhook payloads (Step 5: /webhooks/scalekit and Step 6: event handler), which are parsed and used to drive create/update/deactivate logic and thus can materially influence behavior despite the recommended signature checks.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 19, 2026, 04:06 AM
Issues
1