syncfusion-angular-chat-ui
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of technical documentation, reference guides, and code examples for implementing a chat UI component. No malicious instructions, prompt injections, or unauthorized scripts were detected.
- [EXTERNAL_DOWNLOADS]: The skill references several official Syncfusion NPM packages and standard development dependencies like axios, express, and marked. These are expected for the component's functionality and are sourced from reputable registries.
- [INDIRECT_PROMPT_INJECTION]: The skill handles potentially untrusted message data through its conversational interface. The documentation follows security best practices by recommending the use of DOMPurify to sanitize content and mitigate XSS risks.
- [CREDENTIALS_SAFE]: The skill includes a dedicated security section that provides instructions on managing API keys and secrets securely using environment variables and backend token servers, rather than hardcoding them in the client-side code.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata