syncfusion-javascript-chart

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill consists of technical documentation and code samples for Syncfusion's charting library. All examples follow standard API usage for the version specified (34.1.29) and use official vendor packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how to bind charts to various external data sources including WebSockets, APIs, and user-input forms. This represents a potential surface for indirect prompt injection if untrusted data is visualized without sanitization. Ingestion points: dataSource property (documented in references/data-handling.md). Boundary markers: Absent in documentation examples. Capability inventory: Rendering HTML/SVG content, data labels, and annotations; exporting to PDF, PNG, and SVG formats (documented in references/advanced-features.md). Sanitization: Not explicitly addressed in basic data binding code samples.
  • [EXTERNAL_DOWNLOADS]: The skill instructions include installing official Syncfusion Node.js packages (@syncfusion/ej2-charts and @syncfusion/ej2-base) as standard dependencies for the tool, which is normal and expected for this vendor's UI component library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:56 PM
Security Audit — agent-trust-hub — syncfusion-javascript-chart