syncfusion-aspnetcore-image-editor

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an interactive image editor that ingests untrusted image data from external users, creating an attack surface where an agent could potentially be influenced by malicious instructions embedded in image metadata or content.
  • Ingestion points: The open() method and selected event handlers, as documented in SKILL.md and references/image-editor-open-save.md, allow the agent to process images provided via Base64, Blobs, and file uploads.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat image data as potentially untrusted or to ignore embedded instructions.
  • Capability inventory: The skill includes capabilities to save images to the local file system via export() and demonstrates patterns for sending image data to remote endpoints using the fetch() API.
  • Sanitization: The skill provides proactive guidance for server-side validation (MIME type and size checks) in the Quick Start section of SKILL.md, though these do not sanitize content embedded within valid image streams.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-image-editor