syncfusion-blazor-dropdowns
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation includes instructions to download and install legitimate NuGet packages (
Syncfusion.Blazor.DropDowns,Syncfusion.Blazor.Themes) and references assets from established CDNs like Cloudflare (cdnjs) and jsDelivr for Bootstrap and Font Awesome. These are all standard development practices for the documented vendor components. - [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for binding UI components to remote data sources (e.g., in
references/autocomplete-data-binding.md). While this pattern technically introduces a surface where untrusted data could enter the agent's context, the skill demonstrates legitimate developer workflows for building data-driven applications. - Ingestion points: Untrusted data enters the context via remote APIs specified in
SfDataManagerURL endpoints (e.g.,references/multiselect-data-binding.md). - Boundary markers: Boundary markers are not present in the UI templates, which is standard for display components.
- Capability inventory: The skill focus is limited to UI selection and display; no high-risk capabilities like arbitrary command execution or file system writes are implemented.
- Sanitization: Code examples include security best practices such as using
Uri.EscapeDataStringwhen sending user input to external APIs (e.g.,references/multiselect-advanced-scenarios.md).
Audit Metadata