skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-image-editor/Gen Agent Trust Hub
syncfusion-javascript-image-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard documentation resource for the Syncfusion Image Editor component. All code examples use placeholders for URLs and local paths.
- [EXTERNAL_DOWNLOADS]: The skill references the installation of the
@syncfusion/ej2-image-editorpackage. This is a legitimate library from Syncfusion Inc, a well-known technology vendor. The documentation proactively advises users to runnpm auditto verify supply-chain integrity. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for processing external data (images and text annotations). It includes explicit security warnings to validate and sanitize URLs before passing them to the
open()method to prevent Server-Side Request Forgery (SSRF) and indirect injection attacks. - [DATA_EXFILTRATION]: While the skill demonstrates how to export images and upload them to a server via fetch, these are standard integration patterns for an image editor and use non-functional placeholder URLs.
Audit Metadata