xaf-blazor-ui
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the
HtmlContentPropertyEditorfor rendering HTML andIJSRuntimefor JavaScript interop. These represent standard framework features but create a potential attack surface for indirect prompt injection if used with untrusted data. - Ingestion points:
HtmlContentPropertyEditor(SKILL.md) - Boundary markers: Absent
- Capability inventory: JavaScript interop via
IJSRuntime(SKILL.md), programmatic navigation and UI updates (SKILL.md) - Sanitization: Not described in the skill content
Audit Metadata