syncfusion-javascript-context-menu

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents methods for ingesting data from external APIs and JSON sources to populate the ContextMenu component. While this creates a potential surface for indirect prompt injection or XSS if the menu content is derived from untrusted user input, the skill specifically instructs users on the use of the enableHtmlSanitizer property (enabled by default) and provides warnings about using untrusted content when sanitization is disabled.
  • Ingestion points: Data is ingested via the items property and mapped using FieldSettingsModel (found in references/data-binding.md and references/api-reference.md).
  • Boundary markers: The skill documentation does not use specific LLM boundary markers but relies on the component's built-in enableHtmlSanitizer feature to manage content safety.
  • Capability inventory: The component has the capability to render HTML templates and execute JavaScript event handlers (select, beforeOpen) based on menu interactions.
  • Sanitization: The skill explicitly documents the enableHtmlSanitizer property in references/advanced-features.md, noting it should only be disabled for trusted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-context-menu