syncfusion-angular-query-builder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface as it processes and parses structured query data (SQL and MongoDB strings) to build UI rules and vice-versa.
  • Ingestion points: Data enters the agent context through methods such as setRulesFromSql, setMongoQuery, setRules, and property bindings like [rule] or [dataSource] (referenced in references/import-export.md and references/api.md).
  • Boundary markers: The SKILL.md file contains a dedicated 'Security & Trust Boundary' section that explicitly prohibits binding to untrusted remote sources and provides clear implementation requirements to the agent.
  • Capability inventory: The skill can generate SQL and MongoDB query strings, manipulate the Query Builder UI, and export rules to JSON formats.
  • Sanitization: The skill recommends the use of parameterized SQL (getParameterizedSql) and emphasizes the necessity of server-side sanitization and allow-listing for all exported queries before backend execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:54 PM
Security Audit — agent-trust-hub — syncfusion-angular-query-builder