syncfusion-javascript-carousel

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The Carousel component utilizes custom HTML templates and data binding, which represents a potential surface for indirect prompt injection if external data is rendered without proper sanitization.
  • Ingestion points: Untrusted data may enter through the items array or the dataSource properties as described in SKILL.md and references/populating-items.md.
  • Boundary markers: No explicit delimiters or boundary markers for template content are specified in the documentation examples.
  • Capability inventory: The component renders HTML templates and can execute logic within template functions.
  • Sanitization: The documentation does not explicitly detail sanitization procedures for the data bound to templates, which is common for library-level documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:54 PM
Security Audit — agent-trust-hub — syncfusion-javascript-carousel