syncfusion-blazor-file-manager
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a file manager that ingests data from external file systems and cloud storage providers.
- Ingestion points: Metadata such as file names, paths, and folder structures are ingested from various remote backends (Azure Blob Storage, Amazon S3, Google Drive, SharePoint, SQL databases, and FTP servers) as described in
references/file-providers.mdandreferences/data-binding.md. - Boundary markers: There are no explicit instructions to the AI agent to ignore instructions embedded within file names or other metadata when presenting them to the user.
- Capability inventory: The skill possesses significant capabilities to modify state, including file deletion (
ItemsDeleting), folder creation (FolderCreating), file moving/copying (ItemsMoving), and file uploads as detailed inreferences/file-operations.md. - Sanitization: The documentation proactively recommends server-side sanitization patterns, such as validating file names via
Path.GetFileNameand canonicalizing paths to prevent traversal, as seen in the code examples inreferences/upload-download.md. - [EXTERNAL_DOWNLOADS]: The skill documentation instructs developers to download official libraries.
- Evidence: The skill specifies the installation of
Syncfusion.Blazor.FileManagerandSyncfusion.Blazor.ThemesNuGet packages inreferences/getting-started.md. These are official resources provided by the vendor, Syncfusion Inc.
Audit Metadata