syncfusion-angular-menu

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents features for binding the menu component to external and remote data sources, such as OData services via Syncfusion's DataManager. This creates a potential surface for indirect prompt injection if the data source contains malicious instructions intended to influence an agent processing the menu's state.
  • Ingestion points: Remote data fetching using DataManager and executeQuery in references/data-source-binding.md, as well as hierarchical data binding in references/menu-items.md.
  • Boundary markers: The enableHtmlSanitizer property is highlighted as a security feature to prevent XSS, though it does not explicitly address prompt injection delimiters.
  • Capability inventory: The component supports navigation via the url property and custom rendering through Angular templates, which could be misused if bound to malicious data.
  • Sanitization: A built-in HTML sanitizer is available and enabled by default to protect against script injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:55 PM
Security Audit — agent-trust-hub — syncfusion-angular-menu