syncfusion-blazor-treeview
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates a pattern for highlighting search results in
references/advanced-features.mdthat is vulnerable to indirect injection and cross-site scripting (XSS) due to the use of@Html.Rawon unsanitized data. - Ingestion points: The skill ingests untrusted data from the data source (e.g.,
FolderName) and user input (e.g.,SearchText) in thereferences/advanced-features.mdsearch highlighting example. - Boundary markers: No boundary markers or 'ignore' instructions are used to prevent the interpretation of embedded instructions or malicious scripts within the processed text.
- Capability inventory: The use of
@Html.Rawprovides a direct capability to execute arbitrary HTML and JavaScript in the user's browser. - Sanitization: The
HighlightSearchTexthelper method does not include HTML encoding, meaning any HTML tags present in the source data or search query will be rendered literally by the browser.
Audit Metadata