syncfusion-angular-heatmap

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the official @syncfusion/ej2-angular-heatmap package from the standard NPM registry. As Syncfusion is an established and well-known software vendor, these references are legitimate for the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates how to ingest data into the heatmap component via the dataSource property.
  • Ingestion points: External data is ingested through the [dataSource] property and DataManager configurations across multiple reference examples (e.g., references/data-binding.md).
  • Boundary markers: The component uses standard Angular data binding which implicitly delimits data from executable code.
  • Capability inventory: The component is restricted to visual rendering; no file-system write operations or non-whitelisted network communications are present.
  • Sanitization: Content rendering is handled by the Syncfusion component's internal SVG/Canvas logic, which typically includes protections against script injection in rendered tooltips and labels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:55 PM
Security Audit — agent-trust-hub — syncfusion-angular-heatmap