syncfusion-blazor-common
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references JavaScript files from
https://cdn.syncfusion.comand localization resources fromhttps://github.com/syncfusion/blazor-locale. Both sources are official vendor resources belonging to the skill author (Syncfusion). - [COMMAND_EXECUTION]: The documentation includes standard .NET CLI commands such as
dotnet new blazoranddotnet add packagefor project creation and dependency management. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect injection as it ingests external data (NuGet packages, CDN scripts, and resource files). However, it follows safety best practices by explicitly instructing the agent to request user permission before downloading resources from external repositories.
- Ingestion points: NuGet package installation, script loading from
cdn.syncfusion.com, and resource file downloads fromgithub.com/syncfusion/blazor-locale. - Boundary markers: The skill contains a specific warning: "ASK PERMISSION BEFORE DOWNLOAD THIS" regarding the GitHub localization files.
- Capability inventory: Includes project file creation, NuGet package addition via CLI, and C#/Razor code generation.
- Sanitization: Standard .NET resource handling is assumed; no custom sanitization is performed on the downloaded content by the skill itself.
- [SAFE]: No hardcoded credentials, persistence mechanisms, or obfuscated code were found. The skill instructions encourage safe practices, such as avoiding non-standard NuGet configurations and using official package sources.
Audit Metadata