syncfusion-blazor-datamanager
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install standard NuGet packages from the vendor (Syncfusion.Blazor.Data and Syncfusion.Blazor.Themes). These are established packages from the official organization.
- [INDIRECT_PROMPT_INJECTION]: The skill handles data ingestion from remote endpoints (OData, GraphQL, Web API), which represents a vulnerability surface for indirect prompt injection if an external API is compromised. The skill proactively addresses this by providing the following security framework:
- Ingestion points: Data is fetched via the
Urlproperty of theSfDataManagercomponent in files such asSKILL.mdandreferences/data-binding.md. - Boundary markers: Code examples explicitly implement endpoint whitelisting using
HashSet<string>and validation logic within theOnInitializedlifecycle method. - Capability inventory: The skill maps remote data to UI components (SfGrid, SfDropDownList) and performs CRUD operations via adaptors.
- Sanitization: The instructions mandate server-side schema validation, strongly-typed model mapping, and the use of Blazor's built-in XSS protection for rendered content.
- [COMMAND_EXECUTION]: The skill mentions the
dotnet add packagecommand for dependency management. This is a standard development operation and is used appropriately within the context of getting started with the library.
Audit Metadata