syncfusion-aspnetmvc-docx-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation and reference snippets include links to CSS and JavaScript assets hosted on cdn.syncfusion.com. These are official vendor resources necessary for initializing the ASP.NET MVC component and are considered safe within the context of the vendor's own skill.
  • [CREDENTIALS_UNSAFE]: Features involving document protection (e.g., read-only or comments-only modes) use descriptive placeholders such as 'myPassword' and '{{ protectionPassword }}' in place of actual secrets. Additionally, the skill's key rules explicitly forbid hardcoding license keys, directing users toward environment variables or configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill generates code for handling user-supplied text during document operations like find-and-replace or comment addition. 1. Ingestion points: User-provided strings for search/replace and comment text. 2. Boundary markers: No specific delimiters or safety instructions are defined for user-supplied content within the generated snippets. 3. Capability inventory: Generates Razor views and client-side JavaScript for document manipulation. 4. Sanitization: No explicit sanitization logic is provided in the reference snippets, as the skill focuses on component API usage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:01 AM
Security Audit — agent-trust-hub — syncfusion-aspnetmvc-docx-editor