skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-inline-ai-assist/Gen Agent Trust Hub
syncfusion-javascript-inline-ai-assist
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from various external AI services and provides mechanisms to render this content in the user interface.
- Ingestion points: Untrusted data enters the component via the
promptRequestevent and theexecutePromptmethod as documented inSKILL.mdandreferences/ai-service-integrations.md. - Boundary markers: The documentation does not demonstrate the use of boundary markers or instructions to the AI to ignore embedded commands in the processed data.
- Capability inventory: The component has the capability to modify the Document Object Model (DOM) directly. Multiple examples in
SKILL.mdandreferences/getting-started.mdshow the component updating page content usinginnerHTML(e.g.,document.getElementById('content').innerHTML = args.response). - Sanitization: While some examples utilize the
markedlibrary for markdown parsing, several code snippets demonstrate direct assignment of AI responses toinnerHTMLwithout explicit sanitization or escaping, which could allow execution of malicious scripts (XSS) if the AI service is compromised or manipulated. - [EXTERNAL_DOWNLOADS]: The documentation references the installation and use of several external resources and dependencies.
- Fetches component styles and base configurations from the vendor's official CDN (
cdn.syncfusion.com). - References standard utility scripts from well-known services like Cloudflare (
cdnjs.cloudflare.com). - Recommends the installation of official library packages including
@syncfusion/ej2-interactive-chat,openai,@google/generative-ai,marked, andhighlight.js.
Audit Metadata