syncfusion-angular-treeview

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the ingestion and display of hierarchical data from external sources, including remote APIs and OData services. This creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions targeting the AI agent or the application logic.\n
  • Ingestion points: Data binding examples in 'references/data-binding.md' use 'DataManager' to fetch data from remote URLs and local arrays.\n
  • Boundary markers: The documentation does not specify boundary markers or instructions for the agent to ignore content within the data structures.\n
  • Capability inventory: The skill is limited to UI component configuration and data management within a web application context; it does not include subprocess execution, file writing, or system-level network operations.\n
  • Sanitization: While standard Angular templates provide escaping, the documentation also provides examples of using 'innerHTML' in 'references/templating.md' for custom node rendering, which represents a potential XSS surface if data is not sanitized.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:55 PM
Security Audit — agent-trust-hub — syncfusion-angular-treeview