Summary
The AI chat pipeline returns raw Azure OpenAI output directly to users with no output validation, PII detection, content safety filtering, or structured output enforcement. This means harmful, policy-violating, or sensitive content generated by the model would be passed straight through.
Affected Code
EssentialCSharp.Web/Controllers/ChatController.cs — both /api/chat/message and /api/chat/stream:
// Non-streaming: raw model text returned without any inspection
return Ok(new ChatMessageResponse { Response = response, ... });
// Streaming: raw delta text written directly to SSE stream
var eventData = JsonSerializer.Serialize(new { type = "text", data = text });
await Response.WriteAsync($"data: {eventData}\n\n", cancellationToken);
AIChatService.cs — GetChatCompletionCore returns responseText from the model with no post-processing.
There is also no content safety check on user input before it is sent to the model.
Risk
OWASP AI Agent Security — Risk #5: Output Validation & Guardrails / Risk #8: Sensitive Data Exposure
- A jailbroken or misconfigured model could return harmful content, credentials from its training data, or PII.
- No defense against the model leaking content from its system prompt or injected context back to the user.
- No enforcement that outputs conform to expected shape (e.g., markdown response about C# topics only).
Recommended Mitigations
- Integrate Azure AI Content Safety for both input (before sending to model) and output (before returning to client):
// In AIChatService or a middleware wrapper:
var inputSafety = await contentSafetyClient.AnalyzeTextAsync(prompt);
if (inputSafety.Value.CategoriesAnalysis.Any(c => c.Severity > 2))
return ("Content policy violation.", null);
- Apply a system prompt instruction bounding output scope: "Only respond about C# and Essential C# book topics."
- Screen output for PII patterns (emails, phone numbers, SSNs) before streaming/returning:
private static readonly Regex PiiPattern = new(@"\b\d{3}-\d{2}-\d{4}\b|\b[\w.]+@[\w.]+\b", RegexOptions.Compiled);
- Set
max_output_tokens on the ResponseCreationOptions to enforce an output length cap and prevent runaway generation costs.
References
Summary
The AI chat pipeline returns raw Azure OpenAI output directly to users with no output validation, PII detection, content safety filtering, or structured output enforcement. This means harmful, policy-violating, or sensitive content generated by the model would be passed straight through.
Affected Code
EssentialCSharp.Web/Controllers/ChatController.cs— both/api/chat/messageand/api/chat/stream:AIChatService.cs—GetChatCompletionCorereturnsresponseTextfrom the model with no post-processing.There is also no content safety check on user input before it is sent to the model.
Risk
OWASP AI Agent Security — Risk #5: Output Validation & Guardrails / Risk #8: Sensitive Data Exposure
Recommended Mitigations
max_output_tokenson theResponseCreationOptionsto enforce an output length cap and prevent runaway generation costs.References