skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-context-menu/Gen Agent Trust Hub
syncfusion-javascript-context-menu
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents methods for ingesting data from external APIs and JSON sources to populate the ContextMenu component. While this creates a potential surface for indirect prompt injection or XSS if the menu content is derived from untrusted user input, the skill specifically instructs users on the use of the
enableHtmlSanitizerproperty (enabled by default) and provides warnings about using untrusted content when sanitization is disabled. - Ingestion points: Data is ingested via the
itemsproperty and mapped usingFieldSettingsModel(found inreferences/data-binding.mdandreferences/api-reference.md). - Boundary markers: The skill documentation does not use specific LLM boundary markers but relies on the component's built-in
enableHtmlSanitizerfeature to manage content safety. - Capability inventory: The component has the capability to render HTML templates and execute JavaScript event handlers (
select,beforeOpen) based on menu interactions. - Sanitization: The skill explicitly documents the
enableHtmlSanitizerproperty inreferences/advanced-features.md, noting it should only be disabled for trusted content.
Audit Metadata