syncfusion-dotnet-markdown

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: In Mode 2 (Document Generation), the skill generates a temporary .csx script by interpolating API logic from reference files and user-supplied parameters (such as file paths and document content) into a base template. This script is then executed by the agent environment.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes the dotnet script command-line tool to execute the dynamically generated C# scripts, enabling arbitrary code execution within the agent's permission context.
  • [EXTERNAL_DOWNLOADS]: The template.csx file includes NuGet package directives (#r "nuget: Syncfusion.Markdown" and #r "nuget: Syncfusion.Licensing") that trigger the download of external libraries from public or private NuGet registries during script execution.
  • [DATA_EXPOSURE]: The skill templates and instructions are designed to access sensitive license information from the SYNCFUSION_LICENSE_KEY environment variable and a SyncfusionLicense.txt file located in the user's workspace root.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect injection as it reads and parses untrusted markdown files. These files enter the agent's context and are used to drive the generation of execution scripts. Maliciously crafted document content could attempt to influence the script's logic or downstream file operations, as the skill lacks explicit sanitization instructions for interpolated document data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 09:59 AM
Security Audit — agent-trust-hub — syncfusion-dotnet-markdown