syncfusion-javascript-inline-ai-assist

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/ai-service-integrations.md

The code is documentation for legitimate AI-service integrations and contains no strong evidence of malware or intentional supply-chain sabotage. It does contain meaningful application security risks: client-side API key exposure when browser examples are used, transmission of prompts to external services, and potential XSS through unsanitized markdown and direct `innerHTML` assignment. Production implementations should proxy requests through a trusted backend, keep credentials server-side, sanitize generated HTML, prefer safe text rendering, validate response status and schemas, and use HTTPS.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:57 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Fjavascript-ui-controls-skills%2Fsyncfusion-javascript-inline-ai-assist%2F@cba94dbf61ab451beff40a94f1ff29e1ac3237c8f52e3780ec95d0d2fdda7c66
Security Audit — socket — syncfusion-javascript-inline-ai-assist