syncfusion-blazor-file-manager

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a file manager that ingests data from external file systems and cloud storage providers.
  • Ingestion points: Metadata such as file names, paths, and folder structures are ingested from various remote backends (Azure Blob Storage, Amazon S3, Google Drive, SharePoint, SQL databases, and FTP servers) as described in references/file-providers.md and references/data-binding.md.
  • Boundary markers: There are no explicit instructions to the AI agent to ignore instructions embedded within file names or other metadata when presenting them to the user.
  • Capability inventory: The skill possesses significant capabilities to modify state, including file deletion (ItemsDeleting), folder creation (FolderCreating), file moving/copying (ItemsMoving), and file uploads as detailed in references/file-operations.md.
  • Sanitization: The documentation proactively recommends server-side sanitization patterns, such as validating file names via Path.GetFileName and canonicalizing paths to prevent traversal, as seen in the code examples in references/upload-download.md.
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs developers to download official libraries.
  • Evidence: The skill specifies the installation of Syncfusion.Blazor.FileManager and Syncfusion.Blazor.Themes NuGet packages in references/getting-started.md. These are official resources provided by the vendor, Syncfusion Inc.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:39 PM
Security Audit — agent-trust-hub — syncfusion-blazor-file-manager