syncfusion-aspnetcore-diagram

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill includes 'STRICT USAGE RULES' that instruct the agent to ignore its training data and external knowledge, and provides specific error messages to return if features are not documented in the reference files.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data to generate diagram nodes, labels, and HTML content, creating a surface for potential indirect prompt injection.\n
  • Ingestion points: Data is ingested via dataSourceSettings and ViewBag bindings as shown in references/data-binding.md.\n
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are provided for processed data records.\n
  • Capability inventory: The component supports exportDiagram for file generation, HTML shapes for rendering markup, and Hyperlink annotations for node interaction.\n
  • Sanitization: No explicit sanitization or validation of input data is implemented in the provided reference scripts.\n- [COMMAND_EXECUTION]: The setup instructions include a PowerShell command Install-Package Syncfusion.EJ2.AspNet.Core for environment configuration.\n- [EXTERNAL_DOWNLOADS]: The skill references official CSS and JavaScript resources from the cdn.syncfusion.com domain, which is associated with the well-known vendor Syncfusion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-diagram