skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-dashboard-layout/Gen Agent Trust Hub
syncfusion-javascript-dashboard-layout
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of documentation and code examples for a legitimate UI component library. The instructions and code samples are educational and align with the primary purpose of UI layout management without introducing malicious behavior or unexpected capabilities.
- [INDIRECT_PROMPT_INJECTION]: The DashboardLayout component supports custom HTML content within panel headers and bodies, which represents a potential injection surface if the rendered content is derived from untrusted sources. * Ingestion points: The 'content' and 'header' properties in the panel configuration array, as documented in references/panel-configuration.md and references/api-reference.md. * Boundary markers: The API includes an 'enableHtmlSanitizer' property, which is explicitly recommended in the documentation to enhance security. * Capability inventory: The skill is restricted to UI rendering and state management; it does not involve subprocess execution, network exfiltration of local data, or system-level modifications. * Sanitization: Built-in sanitization logic is provided by the @syncfusion/ej2-layouts library and can be toggled via the enableHtmlSanitizer configuration setting.
Audit Metadata