syncfusion-angular-range-navigator

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates patterns for remote data binding in references/getting-started.md and references/series-types.md, which exposes the agent to indirect prompt injection risks.
  • Ingestion points: Data is fetched from external API endpoints (e.g., https://api.example.com/data) and assigned to the component's dataSource property.
  • Boundary markers: The documentation does not specify the use of delimiters or instructions to prevent the agent from accidentally executing commands embedded in the retrieved data.
  • Capability inventory: The component possesses capabilities to export content to the local filesystem (PNG, PDF, SVG) and invoke system printing, which could be leveraged if malicious instructions were successfully injected through a data source.
  • Sanitization: There is no demonstration of data validation or sanitization of the remote content before it is processed by the component.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 12:21 PM
Security Audit — agent-trust-hub — syncfusion-angular-range-navigator