syncfusion-aspnetcore-inline-ai-assist

Warn

Audited by Socket on Sep 22, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/events-and-handlers.md

This is a benign UI demonstration with no apparent malware or supply-chain attack behavior. It contains two potential DOM XSS weaknesses: prompt/event data is inserted into the event log via innerHTML, and the accepted response is inserted into editable content via innerHTML without sanitization. Use textContent for logs and sanitize or safely construct DOM nodes for response content, especially when responses may come from an external AI service.

Confidence: 97%Severity: 58%
AnomalyLOW
references/advanced-features.md

The fragment is documentation and sample UI code, not malware. It contains a potential DOM XSS vulnerability because an AI/component response is assigned directly to innerHTML without sanitization. Use textContent for plain text or sanitize the response with a well-configured HTML sanitizer before insertion. No evidence of supply-chain malware or unauthorized system activity is present.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 22, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Faspnetcore-ui-components-skills%2Fsyncfusion-aspnetcore-inline-ai-assist%2F@147007346bc8b05264a6a25722198391c279c061f837ba241facdb62045c3648
Security Audit — socket — syncfusion-aspnetcore-inline-ai-assist