syncfusion-blazor-pivot-table
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides functionality for the agent to bind and process data from external remote sources, which is a potential surface for indirect prompt injection if untrusted data is processed.
- Ingestion points: Data ingestion occurs through
PivotViewDataSourceSettings.DataSourceand remote data adaptors likeWebApiAdaptorviaSfDataManager.Url, as documented inSKILL.mdandreferences/data-binding.md. - Boundary markers: The documentation explicitly instructs users and agents to use authenticated endpoints and secure configuration, and provides architectural patterns to isolate data processing from the client.
- Capability inventory: The component performs data aggregation, layout rendering, and can trigger network requests to endpoints defined in the configuration. It does not perform arbitrary system command execution.
- Sanitization: The skill includes a dedicated 'Security Warning: Data Source Validation' section in
SKILL.mdandreferences/data-binding.md, which mandates validation and sanitization of all data received from external sources before binding. - [EXTERNAL_DOWNLOADS]: The skill references official NuGet packages and GitHub repositories for its operations.
- Evidence: The documentation points to
Syncfusion.Blazor.PivotTable,Syncfusion.Blazor.AI, and examples hosted on thegithub.com/syncfusionorganization. These are vendor-owned resources used for the skill's primary purpose and are considered safe. - [SAFE]: The skill provides explicit 'Best Practice' sections teaching the agent how to avoid security pitfalls such as hardcoded credentials and SQL injection by using
IConfigurationand parameterized queries in server-side services.
Audit Metadata