syncfusion-javascript-carousel
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The Carousel component utilizes custom HTML templates and data binding, which represents a potential surface for indirect prompt injection if external data is rendered without proper sanitization.
- Ingestion points: Untrusted data may enter through the
itemsarray or thedataSourceproperties as described inSKILL.mdandreferences/populating-items.md. - Boundary markers: No explicit delimiters or boundary markers for template content are specified in the documentation examples.
- Capability inventory: The component renders HTML templates and can execute logic within template functions.
- Sanitization: The documentation does not explicitly detail sanitization procedures for the data bound to templates, which is common for library-level documentation.
Audit Metadata