devexpress-wpf-ai-chat-control

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECREDENTIALS_UNSAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file 'examples/App.config' contains hardcoded credentials ('demo'). These are explicitly identified by the author as publicly available, rate-limited credentials for the vendor's own evaluation endpoint ('api.devexpress.com') and are intended solely for testing and evaluation purposes during the quickstart process.\n- [SAFE]: The skill demonstrates security best practices by documenting the risk of Indirect Prompt Injection (Category 8). It provides a concrete implementation pattern using the 'HtmlSanitizer' library to sanitize Markdown content generated by the AI before it is rendered as HTML in the WPF application, effectively mitigating potential XSS vulnerabilities.\n- [EXTERNAL_DOWNLOADS]: The skill references several standard NuGet packages including 'DevExpress.AIIntegration.Wpf.Chat', 'Microsoft.Extensions.AI', and 'Azure.AI.OpenAI'. These packages originate from the vendor's own ecosystem or well-known, trusted organizations, following standard development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — devexpress-wpf-ai-chat-control