syncfusion-javascript-dropdowntree

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references external CSS themes hosted on cdn.syncfusion.com and provides links to clone example repositories from the SyncfusionExamples GitHub organization.\n- [COMMAND_EXECUTION]: The skill includes shell commands for environment setup, specifically npm install for package management and git clone for retrieving starter projects.\n- [INDIRECT_PROMPT_INJECTION]: The component accepts hierarchical data via the dataSource property, which is then rendered in the browser. This creates an attack surface for indirect prompt injection or XSS if the data source contains malicious content that is not properly sanitized before being passed to the component.\n
  • Ingestion points: dataSource property configured in SKILL.md and references/data-binding.md.\n
  • Boundary markers: The EJ2 template engine uses ${} delimiters for data binding.\n
  • Capability inventory: The skill allows remote data fetching through DataManager and dynamic DOM rendering.\n
  • Sanitization: The references/templates-and-customization.md file includes a developer warning to properly escape HTML content in production environments.\n- [DYNAMIC_EXECUTION]: Employs a template engine to dynamically generate HTML content based on data object properties using the ${fieldName} syntax.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-dropdowntree