syncfusion-blazor-common

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references JavaScript files from https://cdn.syncfusion.com and localization resources from https://github.com/syncfusion/blazor-locale. Both sources are official vendor resources belonging to the skill author (Syncfusion).
  • [COMMAND_EXECUTION]: The documentation includes standard .NET CLI commands such as dotnet new blazor and dotnet add package for project creation and dependency management.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect injection as it ingests external data (NuGet packages, CDN scripts, and resource files). However, it follows safety best practices by explicitly instructing the agent to request user permission before downloading resources from external repositories.
  • Ingestion points: NuGet package installation, script loading from cdn.syncfusion.com, and resource file downloads from github.com/syncfusion/blazor-locale.
  • Boundary markers: The skill contains a specific warning: "ASK PERMISSION BEFORE DOWNLOAD THIS" regarding the GitHub localization files.
  • Capability inventory: Includes project file creation, NuGet package addition via CLI, and C#/Razor code generation.
  • Sanitization: Standard .NET resource handling is assumed; no custom sanitization is performed on the downloaded content by the skill itself.
  • [SAFE]: No hardcoded credentials, persistence mechanisms, or obfuscated code were found. The skill instructions encourage safe practices, such as avoiding non-standard NuGet configurations and using official package sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:39 PM
Security Audit — agent-trust-hub — syncfusion-blazor-common