syncfusion-javascript-heat-map

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and visualize two-dimensional data from external sources (e.g., JSON APIs), which could potentially contain malicious instructions or cross-site scripting (XSS) payloads.
  • Ingestion points: The dataSource property is the primary entry point for external data (documented in SKILL.md and references/data-binding.md).
  • Capability inventory: The skill utilizes fetch and XMLHttpRequest to retrieve data from network locations (documented in references/data-binding.md).
  • Boundary markers: No specific delimiters or boundary markers are defined for the data payload to separate data from potential instructions.
  • Sanitization: The skill's API reference (references/API-Refernce_JavaScript.md) correctly identifies the enableHtmlSanitizer property, which is a key security control to prevent script execution from untrusted data sources.
  • [EXTERNAL_DOWNLOADS]: The skill references several external JavaScript dependencies and package installations.
  • Evidence: It uses npm install @syncfusion/ej2-heatmap and loads multiple scripts from https://cdn.syncfusion.com/ (e.g., ej2-base.min.js, ej2-heatmap.min.js).
  • Context: These resources are official vendor libraries provided by the skill's author (Syncfusion) and are necessary for the skill's stated purpose. They are considered safe within this context.
  • [COMMAND_EXECUTION]: The skill provides instructions for using the npm CLI to manage project dependencies.
  • Evidence: npm install @syncfusion/ej2-heatmap in SKILL.md and references/getting-started.md.
  • Context: This is standard behavior for development-oriented skills and involves official vendor packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-heat-map