syncfusion-aspnetcore-query-builder

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an educational and technical reference for a legitimate commercial UI component library (Syncfusion EJ2). All instructions and examples follow standard development practices for the ASP.NET Core framework.
  • [EXTERNAL_DOWNLOADS]: The documentation references Syncfusion's official CDN (cdn.syncfusion.com) for loading JavaScript and CSS assets. This is documented as a trusted dependency, and the skill explicitly provides security guidance on mitigating risks via HTTPS, SRI hashes, and CSP whitelisting.
  • [COMMAND_EXECUTION]: The skill provides standard NuGet package manager commands (Install-Package) to facilitate the installation of official vendor libraries.
  • [DATA_EXPOSURE]: Examples include the use of browser localStorage for component state persistence (enablePersistence), which is a standard feature of the UI component and is correctly documented for its intended purpose.
  • [INDIRECT_PROMPT_INJECTION]: The component handles user-defined rules to generate SQL and MongoDB queries. The skill mitigates potential injection risks by demonstrating the use of parameterized SQL methods (getParameterizedSql), which is the recommended secure approach for data operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-query-builder