syncfusion-aspnetmvc-sparkline

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how to ingest external data for visualization via the DataSource property. This creates a surface for indirect prompt injection if the data source is attacker-controlled.
  • Ingestion points: Data is provided to the component through the DataSource property in the C# controller and CSHTML view (e.g., in references/getting-started.md).
  • Boundary markers: The documentation does not specify the use of boundary markers or delimiters for the provided data.
  • Capability inventory: The skill describes capabilities to execute JavaScript code via events such as PointRegionMouseClick and TooltipInitialize (e.g., in references/api-reference.md).
  • Sanitization: There is no mention of data sanitization or escaping mechanisms for the input data provided to the sparkline.
  • [DYNAMIC_EXECUTION]: The component supports dynamic execution through JavaScript event handlers and tooltip templates.
  • Evidence: The component exposes lifecycle and interaction events (e.g., Load, PointRegionMouseClick) that execute custom JavaScript code (documented in references/api-reference.md).
  • Evidence: Custom tooltip templates can be defined in HTML and referenced by the component (documented in references/user-interaction.md), which involve runtime rendering of data placeholders.
  • [EXTERNAL_DOWNLOADS]: The documentation references external resources for package installation and script loading.
  • Evidence: The skill instructs users to install the Syncfusion.EJ2.MVC5 NuGet package using the Package Manager Console.
  • Evidence: The skill references the Syncfusion CDN (https://cdn.syncfusion.com/ej2/20.4.0/dist/ej2.min.js) for script inclusion in the layout file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:26 PM
Security Audit — agent-trust-hub — syncfusion-aspnetmvc-sparkline