syncfusion-dotnet-word
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill features a task-execution mode (Mode 2) that programmatically generates temporary C# script files (.csx) at runtime and executes them to perform document operations.\n- [COMMAND_EXECUTION]: The skill executes shell commands via the dotnet script tool to run its generated document automation logic.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple formats (DOCX, HTML, Markdown, XML, RTF, TXT), creating an attack surface for content within those files to influence agent behavior.\n
- Ingestion points: The skill ingests external content using constructor and Open method variants across multiple reference files, such as WordDocument(stream) and InsertXHTML().\n
- Boundary markers: No explicit delimiters or instruction-ignore warnings were found in the provided processing templates.\n
- Capability inventory: The skill has significant file-system access (read/write) and local code execution capabilities through Mode 2.\n
- Sanitization: Reference materials do not specify methods for sanitizing or validating document content before processing.\n- [EXTERNAL_DOWNLOADS]: The skill references dependencies from the NuGet registry, including Syncfusion.DocIO.Net.Core and Syncfusion.DocIORenderer.Net.Core, which are standard components for the vendor's library.
Audit Metadata