syncfusion-blazor-datamanager

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install standard NuGet packages from the vendor (Syncfusion.Blazor.Data and Syncfusion.Blazor.Themes). These are established packages from the official organization.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles data ingestion from remote endpoints (OData, GraphQL, Web API), which represents a vulnerability surface for indirect prompt injection if an external API is compromised. The skill proactively addresses this by providing the following security framework:
  • Ingestion points: Data is fetched via the Url property of the SfDataManager component in files such as SKILL.md and references/data-binding.md.
  • Boundary markers: Code examples explicitly implement endpoint whitelisting using HashSet<string> and validation logic within the OnInitialized lifecycle method.
  • Capability inventory: The skill maps remote data to UI components (SfGrid, SfDropDownList) and performs CRUD operations via adaptors.
  • Sanitization: The instructions mandate server-side schema validation, strongly-typed model mapping, and the use of Blazor's built-in XSS protection for rendered content.
  • [COMMAND_EXECUTION]: The skill mentions the dotnet add package command for dependency management. This is a standard development operation and is used appropriately within the context of getting started with the library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:39 PM
Security Audit — agent-trust-hub — syncfusion-blazor-datamanager