syncfusion-angular-inline-ai-assist
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/core-configuration.md
LOWAnomalyLOW
references/core-configuration.md
The code contains no apparent malware or supply-chain sabotage. It is configuration/documentation with ordinary AI UI behavior. Security review is warranted because AI or persisted response content is inserted directly into innerHTML, creating a potential XSS sink, and the frontend OpenAI example could expose an API key if used literally. Conversation persistence in localStorage may also disclose sensitive prompts and responses to same-origin scripts.
Confidence: 98%Severity: 58%
Audit Metadata