syncfusion-angular-common

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill utilizes standard package management commands (ng add, npm install) and licensing tools (npx syncfusion-license activate) that target the official @syncfusion scope, consistent with the vendor's intended functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents features for rendering external data within UI templates and loading localization strings, which represent a potential surface for indirect prompt injection if untrusted data is displayed to an agent.
  • Ingestion points: Grid templates in references/advanced-features.md and localization resources in references/globalization.md allow for external string ingestion.
  • Boundary markers: Not explicitly present in documentation snippets, but standard Angular binding is implied.
  • Capability inventory: The skill does not provide the agent with capabilities to execute arbitrary system commands or perform unauthorized network operations using this data.
  • Sanitization: Documentation in references/advanced-features.md explicitly references "Security best practices and HTML sanitization" as a foundational utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:22 AM
Security Audit — agent-trust-hub — syncfusion-angular-common