syncfusion-aspnetcore-scheduler

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the handling and rendering of calendar data which may be provided by end-users or external APIs.
  • Ingestion points: Data is ingested through the dataSource property and remote fetch calls in references/data-binding.md and references/crud-operations.md.
  • Boundary markers: The documentation explicitly instructs implementers to validate and sanitize inputs server-side.
  • Capability inventory: The skill facilitates appointment management and UI customization; it does not invoke dangerous host-level operations or subprocesses.
  • Sanitization: Implementation examples in references/crud-operations.md utilize HtmlEncoder.Default.Encode for fields like Subject, Location, and Description to prevent cross-site scripting (XSS).
  • [SAFE]: The skill is authored by the official vendor and serves as legitimate technical documentation. It includes detailed security advice for implementers, including rate limiting for recurrence expansions to prevent denial-of-service (DoS) and guidance on anti-forgery tokens (CSRF).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-scheduler