syncfusion-aspnetmvc-inline-ai-assist

Warn

Audited by Socket on Jul 23, 2026

1 alert found:

Anomaly
AnomalyLOW
references/commands-and-response.md

No strong evidence of intentional malware/backdoor behavior is present in the provided code fragment. The main security concern is unsafe rendering: assigning AI-generated content into the DOM via `innerHTML` without visible sanitization/escaping, which could enable DOM XSS depending on upstream/component sanitization. Clipboard writing adds privacy/data exposure risk, and the manual prompt construction introduces prompt steering/control-flow risk rather than direct client compromise.

Confidence: 64%Severity: 60%
Audit Metadata
Analyzed At
Jul 23, 2026, 04:36 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Faspnetmvc-ui-components-skills%2Fsyncfusion-aspnetmvc-inline-ai-assist%2F@5a0b8c75811ab074398ce2e0083203e92bbdd7a8f620c31e39e032a6c104533e
Security Audit — socket — syncfusion-aspnetmvc-inline-ai-assist