syncfusion-java-word

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents features for ingesting and processing external data formats such as HTML, XML, and JSON, which creates a surface for indirect prompt injection attacks.\n
  • Ingestion points: Reference files document techniques to ingest data from external sources, specifically references/html-conversions.md (HTML ingestion), references/xml-conversions.md (XML ingestion), and references/mail-merge.md (JSON and XML data sources).\n
  • Boundary markers: The documentation includes validation methods like isValidXHTML() in references/html-conversions.md to check schema, but lacks explicit instructions for the AI to treat ingested data as untrusted or to ignore embedded instructions.\n
  • Capability inventory: The documented Java code snippets involve extensive file system operations including WordDocument.open() and WordDocument.save(), and Java I/O stream handling across multiple reference files, representing a functional capability that could be exploited if an injection occurs.\n
  • Sanitization: The library provides XHTMLValidationType for schema validation in references/html-conversions.md, helping to maintain data structure integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-java-word