syncfusion-aspnetcore-maps
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references JavaScript assets from Syncfusion's official CDN (
cdn.syncfusion.com) and fetches geographical tile data from established map providers, including Microsoft (Bing Maps and Azure Maps), Mapbox, and OpenStreetMap. These are recognized as trusted organizations or well-known technology services. - [INDIRECT_PROMPT_INJECTION]: The component enables dynamic data rendering through templates that interpolate fields from a
dataSource(e.g., using${Country}in tooltips). This presents a theoretical surface for indirect prompt injection if the source data is malicious. - Ingestion points: Untrusted data enters through the
dataSourceandshapeDataproperties defined in various implementation examples. - Boundary markers: No explicit boundary markers or "ignore embedded instructions" warnings are present in the visualization templates.
- Capability inventory: The skill's functionality is limited to geographical visualization and user interface interactions; it does not contain capabilities for file system modification, network exfiltration of sensitive files, or arbitrary command execution.
- Sanitization: While not explicitly shown in the documentation snippets, standard protection is provided by the ASP.NET Core framework and the component's internal SVG rendering logic.
- Risk Assessment: The risk is classified as low as it is tied to the primary visualization purpose of the component and subject to standard LLM guardrails.
Audit Metadata