syncfusion-angular-chat-ui

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of technical documentation, reference guides, and code examples for implementing a chat UI component. No malicious instructions, prompt injections, or unauthorized scripts were detected.
  • [EXTERNAL_DOWNLOADS]: The skill references several official Syncfusion NPM packages and standard development dependencies like axios, express, and marked. These are expected for the component's functionality and are sourced from reputable registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles potentially untrusted message data through its conversational interface. The documentation follows security best practices by recommending the use of DOMPurify to sanitize content and mitigate XSS risks.
  • [CREDENTIALS_SAFE]: The skill includes a dedicated security section that provides instructions on managing API keys and secrets securely using environment variables and backend token servers, rather than hardcoding them in the client-side code.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 17, 2026, 02:23 AM
Security Audit — agent-trust-hub — syncfusion-angular-chat-ui