syncfusion-javascript-markdown-converter

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent on how to process untrusted Markdown data and render the result as HTML in a browser context.\n
  • Ingestion points: User-provided Markdown strings passed to the MarkdownConverter.toHtml method as described in SKILL.md and references/tohtml-api.md.\n
  • Boundary markers: The documentation does not suggest using delimiters or warnings to prevent the agent from following instructions embedded within the Markdown content being converted.\n
  • Capability inventory: The skill demonstrates the capability to render output to the browser DOM using innerHTML in references/getting-started.md and references/richtexteditor-integration.md.\n
  • Sanitization: The guides do not include instructions for sanitizing the generated HTML before rendering, which is a common vulnerability surface when handling user-authored content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-markdown-converter