syncfusion-aspnetcore-ribbon
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions and examples reference external assets including CSS themes and JavaScript libraries hosted on syncfusion.com, jsdelivr.net, and cloudflare.com.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a surface for processing potentially untrusted data through Ribbon configurations and event handlers.
- Ingestion points: Ribbon item configurations, group headers, and event arguments in Razor views and JavaScript handlers.
- Boundary markers: None identified in the provided documentation examples.
- Capability inventory: UI state management, navigation events, and custom script execution via event callbacks.
- Sanitization: No explicit sanitization or validation logic is demonstrated for the data interpolated into the Ribbon UI.
- [DYNAMIC_EXECUTION]: The component utilizes itemTemplate and popupTemplate properties to allow developers to define custom HTML and logic for Ribbon items, which are rendered at runtime using string interpolation.
Audit Metadata