microsoft-azure-webjobs-extensions-authentication-events-dotnet

Warn

Audited by Snyk on Aug 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In this skill, the runtime reads event payload data passed into the Entra ID custom authentication extension trigger functions (e.g., OnAttributeCollectionSubmit and OnOtpSend consume request.Data values originating from user/credential flows), so outsider-authored free text can reach the workflow without selecting a specific item first.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 11, 2026, 07:59 PM
Issues
1
Security Audit — snyk — microsoft-azure-webjobs-extensions-authentication-events-dotnet