syncfusion-javascript-grid

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a framework for rendering data-driven grids, which creates a surface for indirect prompt injection if processing untrusted data.
  • Ingestion points: Data is ingested via the dataSource property, which can be bound to local arrays or remote API endpoints as described in SKILL.md and references/data-binding.md.
  • Boundary markers: No specific instruction delimiters are provided to segregate data content from the agent's control logic.
  • Capability inventory: The component possesses significant capabilities including programmatic CRUD operations (addRecord, updateRow, deleteRecord), data export functions (excelExport, pdfExport), and the ability to render custom HTML through templates, as detailed in references/programmatic-api.md.
  • Sanitization: Documentation in references/adaptors.md includes explicit security warnings that external data must be validated and sanitized before being processed by the grid component.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:54 PM
Security Audit — agent-trust-hub — syncfusion-javascript-grid