syncfusion-javascript-image-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard documentation resource for the Syncfusion Image Editor component. All code examples use placeholders for URLs and local paths.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the @syncfusion/ej2-image-editor package. This is a legitimate library from Syncfusion Inc, a well-known technology vendor. The documentation proactively advises users to run npm audit to verify supply-chain integrity.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for processing external data (images and text annotations). It includes explicit security warnings to validate and sanitize URLs before passing them to the open() method to prevent Server-Side Request Forgery (SSRF) and indirect injection attacks.
  • [DATA_EXFILTRATION]: While the skill demonstrates how to export images and upload them to a server via fetch, these are standard integration patterns for an image editor and use non-functional placeholder URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-image-editor