syncfusion-flutter-excel
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a code generator that interacts with project files and generates file system operations, creating a surface for indirect prompt injection.\n
- Ingestion points: The skill is designed to read workspace files such as
pubspec.yamlandmain.dartand process natural language user prompts to determine code generation requirements.\n - Boundary markers: Explicit instructions in
SKILL.mdandREADME.mdact as behavioral boundaries, commanding the agent to generate code strictly from reference files and prohibiting the invention of new APIs.\n - Capability inventory: The reference documentation (e.g.,
references/workbook.md,references/images.md) contains code snippets capable of writing data to the file system (File.writeAsBytes) and triggering system-level execution viaOpenFile.open.\n - Sanitization: The skill relies on template-based code generation and instructional constraints; it does not implement programmatic sanitization of the project metadata or user prompts it processes.
Audit Metadata