syncfusion-aspnetcore-carousel

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the use of a dataSource property to populate carousel items, which are then rendered using templates. This creates a surface where the component may process untrusted data containing embedded instructions.
  • Ingestion points: The dataSource attribute in ejs-carousel tags, as described in SKILL.md and references/populating-items.md.
  • Boundary markers: The templates use ${property} syntax for data interpolation within <script type="text/x-template"> blocks.
  • Capability inventory: The component is limited to client-side UI rendering, browser-based navigation, and basic event logging via JavaScript. It does not possess system-level access, file writing capabilities, or non-whitelisted network operations.
  • Sanitization: The documentation does not explicitly cover sanitization methods for the data source, relying on the user's implementation and the underlying library's rendering safety.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources from Syncfusion's official Content Delivery Network (CDN) to provide the necessary styles and scripts for the component.
  • Evidence: The skill instructs the user to include https://cdn.syncfusion.com/ej2/24.1.36/fluent.css and https://cdn.syncfusion.com/ej2/24.1.36/dist/ej2.min.js in the project layout as seen in references/getting-started.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-carousel