syncfusion-javascript-grid
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a framework for rendering data-driven grids, which creates a surface for indirect prompt injection if processing untrusted data.
- Ingestion points: Data is ingested via the
dataSourceproperty, which can be bound to local arrays or remote API endpoints as described inSKILL.mdandreferences/data-binding.md. - Boundary markers: No specific instruction delimiters are provided to segregate data content from the agent's control logic.
- Capability inventory: The component possesses significant capabilities including programmatic CRUD operations (
addRecord,updateRow,deleteRecord), data export functions (excelExport,pdfExport), and the ability to render custom HTML through templates, as detailed inreferences/programmatic-api.md. - Sanitization: Documentation in
references/adaptors.mdincludes explicit security warnings that external data must be validated and sanitized before being processed by the grid component.
Audit Metadata