skills/syncfusion/aspnetcore-ui-components-skills/syncfusion-aspnetcore-carousel/Gen Agent Trust Hub
syncfusion-aspnetcore-carousel
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the use of a
dataSourceproperty to populate carousel items, which are then rendered using templates. This creates a surface where the component may process untrusted data containing embedded instructions. - Ingestion points: The
dataSourceattribute inejs-carouseltags, as described inSKILL.mdandreferences/populating-items.md. - Boundary markers: The templates use
${property}syntax for data interpolation within<script type="text/x-template">blocks. - Capability inventory: The component is limited to client-side UI rendering, browser-based navigation, and basic event logging via JavaScript. It does not possess system-level access, file writing capabilities, or non-whitelisted network operations.
- Sanitization: The documentation does not explicitly cover sanitization methods for the data source, relying on the user's implementation and the underlying library's rendering safety.
- [EXTERNAL_DOWNLOADS]: The skill references external resources from Syncfusion's official Content Delivery Network (CDN) to provide the necessary styles and scripts for the component.
- Evidence: The skill instructs the user to include
https://cdn.syncfusion.com/ej2/24.1.36/fluent.cssandhttps://cdn.syncfusion.com/ej2/24.1.36/dist/ej2.min.jsin the project layout as seen inreferences/getting-started.md.
Audit Metadata