syncfusion-angular-linear-gauge

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for generating UI components that support raw HTML content within annotations. This represents a potential vulnerability surface where malicious or untrusted data processed by the agent could be injected into the generated application templates.
  • Ingestion points: Data provided by users for gauge labels, measurement values, and annotation content as illustrated in SKILL.md and references/interaction-and-events.md.
  • Boundary markers: The instructions do not define boundary markers or delimiters to separate untrusted user data from the generated component logic.
  • Capability inventory: The skill itself contains no scripts with subprocess calls, file writes, or network operations, but it generates Angular code and handles UI events.
  • Sanitization: There is no documentation or guidance provided regarding the sanitization of data before it is interpolated into the content property of HTML-based annotations.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of official vendor packages from the npm registry as part of the standard setup process.
  • Evidence: The command npm install @syncfusion/ej2-angular-lineargauge is documented in references/getting-started.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:54 PM
Security Audit — agent-trust-hub — syncfusion-angular-linear-gauge