syncfusion-blazor-query-builder
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of official Syncfusion NuGet packages (Syncfusion.Blazor.QueryBuilder and Syncfusion.Blazor.Themes) which are necessary for the component's functionality.
- [COMMAND_EXECUTION]: Documentation includes standard .NET CLI commands for package management and application execution (e.g., 'dotnet add package', 'dotnet run') used during the development lifecycle.
- [DATA_EXFILTRATION]: Provides examples for client-side state persistence using the browser's localStorage via IJSRuntime, allowing the application to save and restore query states across sessions.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of complex query rules which are used to generate database-executable strings.
- Ingestion points: Rules can be imported via JSON strings, SQL strings, or URL parameters as shown in references/advanced-features.md and SKILL.md.
- Boundary markers: The code examples do not explicitly show boundary markers for this input, but the component uses a structured RuleModel to encapsulate conditions.
- Capability inventory: The skill demonstrates how to generate SQL and MongoDB queries and store state in localStorage using IJSRuntime.
- Sanitization: The documentation explicitly promotes the use of parameterized SQL export methods (GetParameterSql, GetNamedParameterSql) which separate query logic from data values to prevent injection at the database level.
Audit Metadata