syncfusion-javascript-avatar
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation includes standard development commands such as
npm install,npm start, andnpm run buildwhich are typical for managing dependencies and running a Node.js-based web project. - [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion packages like
@syncfusion/ej2-layoutsand@syncfusion/ej2-lists. These are established software libraries used for UI development. It also describes cloning a template repository using placeholder URLs. - [INDIRECT_PROMPT_INJECTION]: The
ListViewcomponent examples demonstrate data binding via adataSourceand templates. This identifies a surface where external data is ingested and rendered in the UI, which is a standard functional requirement for data-driven components. The risk is managed by the framework's internal templating and sanitization logic.
Audit Metadata