syncfusion-aspnetcore-inline-ai-assist

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a control that processes input from AI services and renders the results into the application DOM. This creates an inherent surface for indirect prompt injection where a malicious AI response could attempt to execute scripts or influence the application. As an AI assistant component, this is a design-inherent characteristic.
  • Ingestion points: The onItemSelect and onPromptRequest handlers in SKILL.md and various reference files process responses from external APIs.
  • Boundary markers: Examples do not demonstrate specific delimiting of AI-generated content.
  • Capability inventory: The provided code snippets demonstrate updating page content using the innerHTML property.
  • Sanitization: The documentation examples do not include explicit sanitization of the AI response string, which is a consideration for developers implementing the control.
  • [EXTERNAL_DOWNLOADS]: The skill references necessary stylesheets and JavaScript libraries from the Syncfusion CDN (cdn.syncfusion.com). These are recognized as legitimate resources provided by the control's vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-inline-ai-assist