syncfusion-javascript-calendars

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to install official npm packages @syncfusion/ej2-calendars and @syncfusion/ej2-base which are the official libraries provided by the vendor Syncfusion Inc.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the renderDayCell event and cellTemplate property, which permit custom HTML rendering within calendar cells. While this is an intended feature of the Syncfusion library, it creates a potential surface for cross-site scripting (XSS) if implementers populate these templates with untrusted external data without proper sanitization.
  • [DATA_EXPOSURE]: The documentation demonstrates a pattern for persisting user-selected date ranges using localStorage in references/daterangepicker-advanced-patterns.md, which is a common and benign web development practice for maintaining UI state.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:12 AM
Security Audit — agent-trust-hub — syncfusion-javascript-calendars