syncfusion-javascript-data-manager

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes functionality for ingesting data from external, untrusted API endpoints. The documentation includes explicit security instructions to mitigate this risk.
  • Ingestion points: Remote API responses are fetched via various adaptors (UrlAdaptor, ODataV4Adaptor, GraphQLAdaptor) as documented in SKILL.md and references/adaptors-guide.md.
  • Boundary markers: SKILL.md mandates a 'Security & Trust Boundary' and 'Critical Security Requirements' section, explicitly warning to 'Prevent indirect prompt injection attacks'.
  • Capability inventory: The skill enables generated code to perform data querying, filtering, and CRUD operations on local and remote datasets.
  • Sanitization: The instructions require developers to 'Validate and sanitize responses' and map data to strongly-typed models to prevent malicious content from influencing the application.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing official Syncfusion packages (e.g., @syncfusion/ej2-data) from the public npm registry. These are standard library dependencies provided by the skill's author.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:54 PM
Security Audit — agent-trust-hub — syncfusion-javascript-data-manager