skills/syncfusion/aspnetcore-ui-components-skills/syncfusion-aspnetcore-speech-to-text/Gen Agent Trust Hub
syncfusion-aspnetcore-speech-to-text
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches JavaScript and CSS resources from the Syncfusion content delivery network (cdn.syncfusion.com). These are standard library dependencies for the control's functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill implements speech-to-text functionality where user voice input is transcribed and processed in real-time. This creates a potential surface for indirect prompt injection if the resulting transcript is used to influence further agent actions or displayed without sanitization.
- Ingestion points: Transcribed text from the Web Speech API is captured via the transcriptChanged event as documented in
references/speech-recognition-features.md. - Boundary markers: The documentation does not provide explicit prompt boundary markers for the transcripts when they are interpolated into the application context.
- Capability inventory: The skill demonstrates JavaScript capabilities to update UI component values and log errors to a local API endpoint using fetch.
- Sanitization: The skill includes dedicated documentation in
references/troubleshooting-and-security.mdrecommending input sanitization (removing HTML tags) and sensitive data detection (regex for passwords/PII) before processing voice input.
Audit Metadata