sap-sac-custom-widget

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Reference documentation and templates mention loading charting libraries such as ECharts, D3.js, Chart.js, Leaflet, and Moment.js from well-known CDNs including jsdelivr.net and unpkg.com. These are treated as safe service domains for frontend assets.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing user-provided artifacts such as prompts, data extracts (CSV), and brand guides to generate widget code. While this constitutes a potential attack surface, the skill provides extensive documentation and templates for sanitization, data boundaries, and manual verification to mitigate this risk.
  • [DYNAMIC_EXECUTION]: The skill's primary purpose is generating and iterating on JavaScript Web Components. It includes a browser-based design runtime and local builder for this purpose, accompanied by detailed guidance on subresource integrity (SRI) and security verification of the generated JavaScript artifacts to ensure they are safe for enterprise use.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:16 AM
Security Audit — agent-trust-hub — sap-sac-custom-widget