syncfusion-blazor-treeview

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates a pattern for highlighting search results in references/advanced-features.md that is vulnerable to indirect injection and cross-site scripting (XSS) due to the use of @Html.Raw on unsanitized data.
  • Ingestion points: The skill ingests untrusted data from the data source (e.g., FolderName) and user input (e.g., SearchText) in the references/advanced-features.md search highlighting example.
  • Boundary markers: No boundary markers or 'ignore' instructions are used to prevent the interpretation of embedded instructions or malicious scripts within the processed text.
  • Capability inventory: The use of @Html.Raw provides a direct capability to execute arbitrary HTML and JavaScript in the user's browser.
  • Sanitization: The HighlightSearchText helper method does not include HTML encoding, meaning any HTML tags present in the source data or search query will be rendered literally by the browser.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:39 PM
Security Audit — agent-trust-hub — syncfusion-blazor-treeview