skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-accumulation-chart/Gen Agent Trust Hub
syncfusion-javascript-accumulation-chart
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches Syncfusion EJ2 libraries from the official vendor CDN (cdn.syncfusion.com) and utilizes standard npm packages (@syncfusion/ej2-charts).
- [INDIRECT_PROMPT_INJECTION]: The skill manages data ingestion from external sources via the
dataSourceproperty, which is subsequently rendered in UI elements that support HTML content (tooltips, annotations, and data label templates). - Ingestion points: Data bound to the
dataSourceproperty of theAccumulationChartcomponent as described inSKILL.mdand referenced inreferences/getting-started.mdandreferences/chart-types.md. - Boundary markers: None explicitly implemented for data values, though the documentation includes developer-focused warnings.
- Capability inventory: Ingested data is used for visual rendering within the client browser; the skill does not implement file system writes or network exfiltration using this data.
- Sanitization: The documentation in
references/API-Refernce_JavaScript.mdandreferences/accessibility-and-advanced.mdhighlights theenableHtmlSanitizerproperty (which defaults tofalse) and explicitly advises developers to enable it when rendering untrusted content to mitigate script injection risks.
Audit Metadata