skills/syncfusion/aspnetcore-ui-components-skills/syncfusion-aspnetcore-blockeditor/Gen Agent Trust Hub
syncfusion-aspnetcore-blockeditor
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides integration guides for the Syncfusion Block Editor, a legitimate UI component from a recognized vendor. The documentation encourages developers to utilize built-in security controls.
- [INDIRECT_PROMPT_INJECTION]: The Block Editor handles untrusted external content via data binding and clipboard operations, creating a potential surface for indirect prompt injection. The skill documentation specifically addresses this by promoting the use of HTML sanitizers and denied tag lists.
- Ingestion points: Content enters via the
blocksproperty and through paste events (beforePasteCleanup). - Boundary markers: The skill documentation guides developers on using
enableHtmlSanitizeranddeniedTagsto process content. - Capability inventory: Capabilities include network requests for collaborative synchronization (Yjs) and potential file system writes via configured image upload endpoints.
- Sanitization: The skill recommends keeping
enableHtmlSanitizerat its default value (true) and configuring strictdeniedTagsto remove executable elements.
Audit Metadata