syncfusion-blazor-smart-rich-text-editor

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation provides instructions to install Ollama (a well-known AI service) using a shell script downloaded from its official domain.
  • Evidence: curl https://ollama.ai/install.sh | sh in references/ai-backends.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted user content (direct typing, pasted HTML, or imported documents) as context for AI-driven text generation.
  • Ingestion points: The SfSmartRichTextEditor component's editing surface and the clipboard ingestion handled by RichTextEditorPasteCleanupSettings (SKILL.md, references/paste-and-cleanup.md).
  • Boundary markers: The component automatically appends context-defining strings to AI prompts, such as " for the selected content" or " for the document content," to separate user instructions from the data (references/assist-view-settings.md).
  • Capability inventory: The skill utilizes capabilities for file uploads to user-defined server endpoints (SaveUrl for images/media) and interacts with external services for document conversion (ServiceUrl for Word/PDF import/export) (references/images-and-media.md, references/import-export.md).
  • Sanitization: Employs a built-in HTML sanitizer enabled by default (EnableHtmlSanitizer) and provides configurable paste filters to remove suspicious tags or attributes (references/properties.md, references/paste-and-cleanup.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:39 PM
Security Audit — agent-trust-hub — syncfusion-blazor-smart-rich-text-editor