syncfusion-flutter-excel

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a code generator that interacts with project files and generates file system operations, creating a surface for indirect prompt injection.\n
  • Ingestion points: The skill is designed to read workspace files such as pubspec.yaml and main.dart and process natural language user prompts to determine code generation requirements.\n
  • Boundary markers: Explicit instructions in SKILL.md and README.md act as behavioral boundaries, commanding the agent to generate code strictly from reference files and prohibiting the invention of new APIs.\n
  • Capability inventory: The reference documentation (e.g., references/workbook.md, references/images.md) contains code snippets capable of writing data to the file system (File.writeAsBytes) and triggering system-level execution via OpenFile.open.\n
  • Sanitization: The skill relies on template-based code generation and instructional constraints; it does not implement programmatic sanitization of the project metadata or user prompts it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-flutter-excel