syncfusion-javascript-ai-assistview

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/generative-ui.md

The fragment appears to be legitimate generative-UI example code, with no clear malicious behavior or supply-chain backdoor. It has a meaningful security weakness: untrusted AI output and tool props are interpolated into HTML without escaping or schema validation, potentially enabling DOM XSS if an attacker can influence the AI response or upstream prompt/data. Use safe DOM APIs or HTML escaping and validate block and tool schemas before rendering.

Confidence: 93%Severity: 62%
AnomalyLOW
references/ai-integrations.md

The code is benign integration documentation with no clear malicious behavior. It contains security weaknesses in its illustrative patterns: exposed client-side API keys and unsanitized AI-generated markdown/HTML rendering may create credential leakage or XSS risks if implemented literally. Prompts and conversation history are intentionally sent to configured AI services. Use a server-side proxy, secret management, input/output controls, and HTML sanitization before rendering.

Confidence: 98%Severity: 53%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:56 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Fjavascript-ui-controls-skills%2Fsyncfusion-javascript-ai-assistview%2F@0fa4a6f3b96c25b3e90ada79d47b64a9f7feb81801c8b89cf41359d896e7944f
Security Audit — socket — syncfusion-javascript-ai-assistview