syncfusion-angular-markdown-converter

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill references dependencies and installation steps from trusted sources and the vendor's official package distributions.
  • Downloads the @syncfusion/ej2-markdown-converter, @syncfusion/ej2-angular-richtexteditor, and @syncfusion/ej2-angular-layouts packages from the official npm registry.
  • References the installation of the Angular CLI from its official package source.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where untrusted Markdown content is ingested and converted to HTML, creating a surface for indirect prompt injection or Cross-Site Scripting (XSS).
  • Ingestion points: User-provided Markdown text is retrieved from textarea elements in SKILL.md, references/getting-started.md, and references/richtexteditor-integration.md.
  • Boundary markers: No specific delimiters or boundary instructions are provided to the agent to isolate the user-controlled data during the conversion process.
  • Capability inventory: Integration examples demonstrate the use of innerHTML to render the converted output in the DOM, which allows for script execution if the input content is malicious.
  • Sanitization: Although security documentation in references/tohtml-api.md advises using Angular's DomSanitizer or external sanitization, several implementation patterns in the skill utilize direct, unsanitized innerHTML assignment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:55 PM
Security Audit — agent-trust-hub — syncfusion-angular-markdown-converter