syncfusion-blazor-pivot-table

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides functionality for the agent to bind and process data from external remote sources, which is a potential surface for indirect prompt injection if untrusted data is processed.
  • Ingestion points: Data ingestion occurs through PivotViewDataSourceSettings.DataSource and remote data adaptors like WebApiAdaptor via SfDataManager.Url, as documented in SKILL.md and references/data-binding.md.
  • Boundary markers: The documentation explicitly instructs users and agents to use authenticated endpoints and secure configuration, and provides architectural patterns to isolate data processing from the client.
  • Capability inventory: The component performs data aggregation, layout rendering, and can trigger network requests to endpoints defined in the configuration. It does not perform arbitrary system command execution.
  • Sanitization: The skill includes a dedicated 'Security Warning: Data Source Validation' section in SKILL.md and references/data-binding.md, which mandates validation and sanitization of all data received from external sources before binding.
  • [EXTERNAL_DOWNLOADS]: The skill references official NuGet packages and GitHub repositories for its operations.
  • Evidence: The documentation points to Syncfusion.Blazor.PivotTable, Syncfusion.Blazor.AI, and examples hosted on the github.com/syncfusion organization. These are vendor-owned resources used for the skill's primary purpose and are considered safe.
  • [SAFE]: The skill provides explicit 'Best Practice' sections teaching the agent how to avoid security pitfalls such as hardcoded credentials and SQL injection by using IConfiguration and parameterized queries in server-side services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:39 PM
Security Audit — agent-trust-hub — syncfusion-blazor-pivot-table