syncfusion-javascript-calendars
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to install official npm packages
@syncfusion/ej2-calendarsand@syncfusion/ej2-basewhich are the official libraries provided by the vendor Syncfusion Inc. - [INDIRECT_PROMPT_INJECTION]: The skill documents the
renderDayCellevent andcellTemplateproperty, which permit custom HTML rendering within calendar cells. While this is an intended feature of the Syncfusion library, it creates a potential surface for cross-site scripting (XSS) if implementers populate these templates with untrusted external data without proper sanitization. - [DATA_EXPOSURE]: The documentation demonstrates a pattern for persisting user-selected date ranges using
localStorageinreferences/daterangepicker-advanced-patterns.md, which is a common and benign web development practice for maintaining UI state.
Audit Metadata