syncfusion-blazor-maps
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill consists of legitimate developer documentation for the Syncfusion Blazor Maps component. It demonstrates a strong security posture by educating users on potential risks and providing hardened code examples.
- [EXTERNAL_DOWNLOADS]: The skill references map tiles and geographic data from well-known services (OpenStreetMap, Google, Microsoft). Following the author context, these resources and the Syncfusion CDN are treated as vendor-provided assets. The documentation explicitly recommends local hosting for production security.
- [INDIRECT_PROMPT_INJECTION]: The skill recognizes that external geographic metadata (GeoJSON properties, tooltips) could be weaponized for indirect prompt injection. It provides robust mitigation strategies, including strict capability boundaries, schema validation, and coordinate normalization to prevent untrusted data from reaching AI agents.
- [DYNAMIC_EXECUTION]: Browser-side state persistence and theme management utilize IJSRuntime. The skill includes mandatory security warnings against injecting user-controlled data into these interop points and recommends Content Security Policy (CSP) headers to prevent unauthorized script execution.
Audit Metadata