syncfusion-aspnetmvc-sparkline
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to ingest external data for visualization via the
DataSourceproperty. This creates a surface for indirect prompt injection if the data source is attacker-controlled. - Ingestion points: Data is provided to the component through the
DataSourceproperty in the C# controller and CSHTML view (e.g., inreferences/getting-started.md). - Boundary markers: The documentation does not specify the use of boundary markers or delimiters for the provided data.
- Capability inventory: The skill describes capabilities to execute JavaScript code via events such as
PointRegionMouseClickandTooltipInitialize(e.g., inreferences/api-reference.md). - Sanitization: There is no mention of data sanitization or escaping mechanisms for the input data provided to the sparkline.
- [DYNAMIC_EXECUTION]: The component supports dynamic execution through JavaScript event handlers and tooltip templates.
- Evidence: The component exposes lifecycle and interaction events (e.g.,
Load,PointRegionMouseClick) that execute custom JavaScript code (documented inreferences/api-reference.md). - Evidence: Custom tooltip templates can be defined in HTML and referenced by the component (documented in
references/user-interaction.md), which involve runtime rendering of data placeholders. - [EXTERNAL_DOWNLOADS]: The documentation references external resources for package installation and script loading.
- Evidence: The skill instructs users to install the
Syncfusion.EJ2.MVC5NuGet package using the Package Manager Console. - Evidence: The skill references the Syncfusion CDN (
https://cdn.syncfusion.com/ej2/20.4.0/dist/ej2.min.js) for script inclusion in the layout file.
Audit Metadata