syncfusion-aspnetcore-rich-text-editor

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents a legitimate UI component with no detected malicious patterns. It provides clear guidance on secure implementation.
  • [EXTERNAL_DOWNLOADS]: The skill fetches JavaScript and CSS resources from trusted and well-known services, including the official Syncfusion CDN and CDNJS. These resources are standard requirements for the editor's UI and its optional integrations like syntax highlighting (CodeMirror) and Markdown rendering (Marked.js).
  • [INDIRECT_PROMPT_INJECTION]: The component features an AI Assistant and processes Markdown content, creating an attack surface for data poisoning. However, the documentation proactively addresses these risks by describing the built-in HTML sanitizer (enabled by default) and providing examples for further client-side and server-side validation using established security libraries.
  • Ingestion points: AI Assistant response payloads fetched via AJAX, content pasted from the clipboard, and external Markdown data processed for rendering.
  • Boundary markers: The editor uses specific DOM target IDs and supports IFrame mode for strict style and content isolation.
  • Capability inventory: The skill documents programmatic command execution, network operations for media uploads, and server-side file management.
  • Sanitization: The built-in sanitizer is active by default. The documentation provides implementation examples for custom sanitization logic via events and recommends server-side validation using the Ganss.Xss NuGet package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-rich-text-editor