syncfusion-dotnet-word

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill features a task-execution mode (Mode 2) that programmatically generates temporary C# script files (.csx) at runtime and executes them to perform document operations.\n- [COMMAND_EXECUTION]: The skill executes shell commands via the dotnet script tool to run its generated document automation logic.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple formats (DOCX, HTML, Markdown, XML, RTF, TXT), creating an attack surface for content within those files to influence agent behavior.\n
  • Ingestion points: The skill ingests external content using constructor and Open method variants across multiple reference files, such as WordDocument(stream) and InsertXHTML().\n
  • Boundary markers: No explicit delimiters or instruction-ignore warnings were found in the provided processing templates.\n
  • Capability inventory: The skill has significant file-system access (read/write) and local code execution capabilities through Mode 2.\n
  • Sanitization: Reference materials do not specify methods for sanitizing or validating document content before processing.\n- [EXTERNAL_DOWNLOADS]: The skill references dependencies from the NuGet registry, including Syncfusion.DocIO.Net.Core and Syncfusion.DocIORenderer.Net.Core, which are standard components for the vendor's library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:28 PM
Security Audit — agent-trust-hub — syncfusion-dotnet-word