syncfusion-aspnetcore-maps

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references JavaScript assets from Syncfusion's official CDN (cdn.syncfusion.com) and fetches geographical tile data from established map providers, including Microsoft (Bing Maps and Azure Maps), Mapbox, and OpenStreetMap. These are recognized as trusted organizations or well-known technology services.
  • [INDIRECT_PROMPT_INJECTION]: The component enables dynamic data rendering through templates that interpolate fields from a dataSource (e.g., using ${Country} in tooltips). This presents a theoretical surface for indirect prompt injection if the source data is malicious.
  • Ingestion points: Untrusted data enters through the dataSource and shapeData properties defined in various implementation examples.
  • Boundary markers: No explicit boundary markers or "ignore embedded instructions" warnings are present in the visualization templates.
  • Capability inventory: The skill's functionality is limited to geographical visualization and user interface interactions; it does not contain capabilities for file system modification, network exfiltration of sensitive files, or arbitrary command execution.
  • Sanitization: While not explicitly shown in the documentation snippets, standard protection is provided by the ASP.NET Core framework and the component's internal SVG rendering logic.
  • Risk Assessment: The risk is classified as low as it is tied to the primary visualization purpose of the component and subject to standard LLM guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-maps