syncfusion-blazor-treegrid
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the DisableHtmlEncode property in references/cell.md, which allows rendering raw HTML in grid cells. This creates a surface for Indirect Prompt Injection or Cross-Site Scripting (XSS) if the grid displays untrusted data.
- Ingestion points: The DataSource property in SKILL.md and references/data-binding.md accepts external data for display.
- Capability inventory: The grid provides data manipulation and support for custom templates that render markup.
- Boundary markers: The documentation includes a security warning: 'Only use with trusted data. Enabling this on user-supplied content can expose XSS vulnerabilities.'
- Sanitization: No built-in sanitization is mentioned; responsibility is delegated to the implementer.
- [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion NuGet packages and themes such as Syncfusion.Blazor.TreeGrid. These are trusted vendor resources.
Audit Metadata