syncfusion-javascript-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references library files hosted on Syncfusion's official CDN (cdn.syncfusion.com) and official NPM packages (@syncfusion/*). These are standard and safe distribution methods for the vendor's resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and extraction of content from PDF documents. If an agent processes untrusted PDF files, there is a potential risk that the file content could contain instructions designed to manipulate the agent's behavior.
  • Ingestion points: Document loading methods documented in getting-started.md and text extraction APIs in text-extraction.md and image-extraction.md.
  • Boundary markers: The provided code examples and instructions do not include specific patterns for using delimiters or boundary markers when handling extracted text.
  • Capability inventory: The skill includes file saving capabilities via document.save() and reference examples for network uploads in split-documents.md.
  • Sanitization: The library and documentation do not provide automatic sanitization of extracted data; developers are expected to handle content safely after extraction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:59 AM
Security Audit — agent-trust-hub — syncfusion-javascript-pdf