syncfusion-javascript-3d-chart
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation in
references/getting-started.mdcontains a script tag referencingcdn.synfusion.cominstead of the officialcdn.syncfusion.com. This character substitution (omitting the 'c') is a signature of typosquatting and represents a risk where malicious code could be served if the domain is registered by a third party. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources (local arrays, remote APIs, WebSockets, and CSV text) to render 3D visualizations, creating an attack surface for malicious data.
- Ingestion points: External data enters the component via the
dataSourceproperty, as shown inSKILL.mdandreferences/data-and-performance.md. - Boundary markers: The documentation includes logic for basic type validation (e.g.,
validateChartDatainSKILL.md) but does not provide instructions to the agent to treat data as untrusted or to ignore embedded instructions. - Capability inventory: The skill uses network operations (
fetch,DataManager,WebSocket) and DOM manipulation to render charts and export them to document formats. - Sanitization: There is no explicit logic for sanitizing string data before it is interpolated into tooltips or data labels, which could lead to cross-site scripting (XSS) or prompt manipulation if the data source is compromised.
- [METADATA_POISONING]: Multiple code blocks in
references/3d-settings-and-rotation.mdandreferences/chart-types-3d.mdcontain corrupted or fragmented text (e.g., 'chart[ Source: chartData, Name: ...'). This suggests the content was improperly processed or generated, which may result in users executing incomplete or malformed code.
Audit Metadata