syncfusion-javascript-docx-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were detected. The skill follows best practices for developer documentation and code generation.
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install official Syncfusion packages from the npm registry (e.g., @syncfusion/ej2-documenteditor). These are legitimate vendor resources.
  • Evidence: README.md, SKILL.md, and references/getting-started.md all reference standard npm installation procedures for the editor component and its themes.
  • [COMMAND_EXECUTION]: The documentation provides standard CLI commands for setting up a development environment (npm install, dotnet build, dotnet run). These are informational and intended for local developer use.
  • Evidence: references/spell-checker.md provides steps for setting up a backend service using the .NET CLI.
  • [CREDENTIALS_UNSAFE]: While snippets in references/document-protection.md use placeholder passwords like '123', these are clearly marked as examples for document-level locking features. The skill explicitly forbids hardcoding sensitive license keys (Rule 5 in SKILL.md).
  • [DATA_EXFILTRATION]: The skill uses a vendor-provided demo endpoint (https://document.syncfusion.com/...) for evaluation purposes and provides a clear warning that users should host their own service for production. No unauthorized data transmission was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:01 AM
Security Audit — agent-trust-hub — syncfusion-javascript-docx-editor