syncfusion-angular-menu
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents features for binding the menu component to external and remote data sources, such as OData services via Syncfusion's DataManager. This creates a potential surface for indirect prompt injection if the data source contains malicious instructions intended to influence an agent processing the menu's state.
- Ingestion points: Remote data fetching using
DataManagerandexecuteQueryinreferences/data-source-binding.md, as well as hierarchical data binding inreferences/menu-items.md. - Boundary markers: The
enableHtmlSanitizerproperty is highlighted as a security feature to prevent XSS, though it does not explicitly address prompt injection delimiters. - Capability inventory: The component supports navigation via the
urlproperty and custom rendering through Angular templates, which could be misused if bound to malicious data. - Sanitization: A built-in HTML sanitizer is available and enabled by default to protect against script injection.
Audit Metadata