skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-ai-assistview/Gen Agent Trust Hub
syncfusion-javascript-ai-assistview
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides building blocks for an AI assistant interface that processes and renders data from external AI providers, creating a potential surface for indirect prompt injection.
- Ingestion points: The component ingests data from external AI services via the
promptRequestevent andaddPromptResponsemethod as described inSKILL.mdandreferences/ai-integrations.md. - Boundary markers: The provided implementation examples do not include explicit boundary markers or instructions to the model to ignore embedded commands within the response data.
- Capability inventory: The documentation demonstrates capabilities such as network requests (
fetchcalls to AI APIs inreferences/ai-integrations.md) and dynamic UI rendering through templates andregisterToolUIinreferences/generative-ui.md. - Sanitization: While the examples suggest using the
markedlibrary to parse markdown inreferences/ai-integrations.md, they do not demonstrate specific XSS sanitization for the final HTML output, which is a common requirement when rendering third-party AI content.
Audit Metadata