syncfusion-javascript-docx-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were detected. The skill follows best practices for developer documentation and code generation.
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install official Syncfusion packages from the npm registry (e.g.,
@syncfusion/ej2-documenteditor). These are legitimate vendor resources. - Evidence:
README.md,SKILL.md, andreferences/getting-started.mdall reference standard npm installation procedures for the editor component and its themes. - [COMMAND_EXECUTION]: The documentation provides standard CLI commands for setting up a development environment (
npm install,dotnet build,dotnet run). These are informational and intended for local developer use. - Evidence:
references/spell-checker.mdprovides steps for setting up a backend service using the .NET CLI. - [CREDENTIALS_UNSAFE]: While snippets in
references/document-protection.mduse placeholder passwords like'123', these are clearly marked as examples for document-level locking features. The skill explicitly forbids hardcoding sensitive license keys (Rule 5 inSKILL.md). - [DATA_EXFILTRATION]: The skill uses a vendor-provided demo endpoint (
https://document.syncfusion.com/...) for evaluation purposes and provides a clear warning that users should host their own service for production. No unauthorized data transmission was found.
Audit Metadata