syncfusion-angular-query-builder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface as it processes and parses structured query data (SQL and MongoDB strings) to build UI rules and vice-versa.
- Ingestion points: Data enters the agent context through methods such as
setRulesFromSql,setMongoQuery,setRules, and property bindings like[rule]or[dataSource](referenced inreferences/import-export.mdandreferences/api.md). - Boundary markers: The
SKILL.mdfile contains a dedicated 'Security & Trust Boundary' section that explicitly prohibits binding to untrusted remote sources and provides clear implementation requirements to the agent. - Capability inventory: The skill can generate SQL and MongoDB query strings, manipulate the Query Builder UI, and export rules to JSON formats.
- Sanitization: The skill recommends the use of parameterized SQL (
getParameterizedSql) and emphasizes the necessity of server-side sanitization and allow-listing for all exported queries before backend execution.
Audit Metadata