syncfusion-javascript-3d-chart

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation in references/getting-started.md contains a script tag referencing cdn.synfusion.com instead of the official cdn.syncfusion.com. This character substitution (omitting the 'c') is a signature of typosquatting and represents a risk where malicious code could be served if the domain is registered by a third party.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources (local arrays, remote APIs, WebSockets, and CSV text) to render 3D visualizations, creating an attack surface for malicious data.
  • Ingestion points: External data enters the component via the dataSource property, as shown in SKILL.md and references/data-and-performance.md.
  • Boundary markers: The documentation includes logic for basic type validation (e.g., validateChartData in SKILL.md) but does not provide instructions to the agent to treat data as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill uses network operations (fetch, DataManager, WebSocket) and DOM manipulation to render charts and export them to document formats.
  • Sanitization: There is no explicit logic for sanitizing string data before it is interpolated into tooltips or data labels, which could lead to cross-site scripting (XSS) or prompt manipulation if the data source is compromised.
  • [METADATA_POISONING]: Multiple code blocks in references/3d-settings-and-rotation.md and references/chart-types-3d.md contain corrupted or fragmented text (e.g., 'chart[ Source: chartData, Name: ...'). This suggests the content was improperly processed or generated, which may result in users executing incomplete or malformed code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-3d-chart