skills/syncfusion/aspnetcore-ui-components-skills/syncfusion-aspnetcore-ai-assistview/Gen Agent Trust Hub
syncfusion-aspnetcore-ai-assistview
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of a chat interface that processes untrusted user input and renders external AI responses, which constitutes a standard attack surface for indirect prompt injection. 1. Ingestion points: The component ingests user data via text prompts, microphone-based voice input, and file attachments as shown in references/events-handling.md and references/speech-to-text.md. 2. Boundary markers: Documentation examples do not explicitly define prompt delimiters or ignore instructions for the processed content. 3. Capability inventory: The component is configured to perform network requests to AI services and manage file uploads through service endpoints. 4. Sanitization: The skill supports rendering markdown content into HTML using the marked library.
- [EXTERNAL_DOWNLOADS]: The skill integrates resources from the vendor's official infrastructure and other well-known services. It references scripts and styles from cdn.syncfusion.com and uses demonstration file service endpoints at services.syncfusion.com. It also loads the marked library from cdn.jsdelivr.net and provides examples for OpenAI and Azure OpenAI integrations.
- [SAFE]: The skill implementation adheres to standard development practices for UI components and uses recognized third-party services and vendor-owned domains.
Audit Metadata