syncfusion-blazor-query-builder

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of official Syncfusion NuGet packages (Syncfusion.Blazor.QueryBuilder and Syncfusion.Blazor.Themes) which are necessary for the component's functionality.
  • [COMMAND_EXECUTION]: Documentation includes standard .NET CLI commands for package management and application execution (e.g., 'dotnet add package', 'dotnet run') used during the development lifecycle.
  • [DATA_EXFILTRATION]: Provides examples for client-side state persistence using the browser's localStorage via IJSRuntime, allowing the application to save and restore query states across sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of complex query rules which are used to generate database-executable strings.
  • Ingestion points: Rules can be imported via JSON strings, SQL strings, or URL parameters as shown in references/advanced-features.md and SKILL.md.
  • Boundary markers: The code examples do not explicitly show boundary markers for this input, but the component uses a structured RuleModel to encapsulate conditions.
  • Capability inventory: The skill demonstrates how to generate SQL and MongoDB queries and store state in localStorage using IJSRuntime.
  • Sanitization: The documentation explicitly promotes the use of parameterized SQL export methods (GetParameterSql, GetNamedParameterSql) which separate query logic from data values to prevent injection at the database level.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:39 PM
Security Audit — agent-trust-hub — syncfusion-blazor-query-builder