syncfusion-javascript-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation references library files hosted on Syncfusion's official CDN (
cdn.syncfusion.com) and official NPM packages (@syncfusion/*). These are standard and safe distribution methods for the vendor's resources. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and extraction of content from PDF documents. If an agent processes untrusted PDF files, there is a potential risk that the file content could contain instructions designed to manipulate the agent's behavior.
- Ingestion points: Document loading methods documented in
getting-started.mdand text extraction APIs intext-extraction.mdandimage-extraction.md. - Boundary markers: The provided code examples and instructions do not include specific patterns for using delimiters or boundary markers when handling extracted text.
- Capability inventory: The skill includes file saving capabilities via
document.save()and reference examples for network uploads insplit-documents.md. - Sanitization: The library and documentation do not provide automatic sanitization of extracted data; developers are expected to handle content safely after extraction.
Audit Metadata