syncfusion-aspnetcore-speech-to-text

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches JavaScript and CSS resources from the Syncfusion content delivery network (cdn.syncfusion.com). These are standard library dependencies for the control's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements speech-to-text functionality where user voice input is transcribed and processed in real-time. This creates a potential surface for indirect prompt injection if the resulting transcript is used to influence further agent actions or displayed without sanitization.
  • Ingestion points: Transcribed text from the Web Speech API is captured via the transcriptChanged event as documented in references/speech-recognition-features.md.
  • Boundary markers: The documentation does not provide explicit prompt boundary markers for the transcripts when they are interpolated into the application context.
  • Capability inventory: The skill demonstrates JavaScript capabilities to update UI component values and log errors to a local API endpoint using fetch.
  • Sanitization: The skill includes dedicated documentation in references/troubleshooting-and-security.md recommending input sanitization (removing HTML tags) and sensitive data detection (regex for passwords/PII) before processing voice input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-speech-to-text