syncfusion-javascript-heat-map
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and visualize two-dimensional data from external sources (e.g., JSON APIs), which could potentially contain malicious instructions or cross-site scripting (XSS) payloads.
- Ingestion points: The
dataSourceproperty is the primary entry point for external data (documented inSKILL.mdandreferences/data-binding.md). - Capability inventory: The skill utilizes
fetchandXMLHttpRequestto retrieve data from network locations (documented inreferences/data-binding.md). - Boundary markers: No specific delimiters or boundary markers are defined for the data payload to separate data from potential instructions.
- Sanitization: The skill's API reference (
references/API-Refernce_JavaScript.md) correctly identifies theenableHtmlSanitizerproperty, which is a key security control to prevent script execution from untrusted data sources. - [EXTERNAL_DOWNLOADS]: The skill references several external JavaScript dependencies and package installations.
- Evidence: It uses
npm install @syncfusion/ej2-heatmapand loads multiple scripts fromhttps://cdn.syncfusion.com/(e.g.,ej2-base.min.js,ej2-heatmap.min.js). - Context: These resources are official vendor libraries provided by the skill's author (Syncfusion) and are necessary for the skill's stated purpose. They are considered safe within this context.
- [COMMAND_EXECUTION]: The skill provides instructions for using the
npmCLI to manage project dependencies. - Evidence:
npm install @syncfusion/ej2-heatmapinSKILL.mdandreferences/getting-started.md. - Context: This is standard behavior for development-oriented skills and involves official vendor packages.
Audit Metadata