skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-markdown-converter/Gen Agent Trust Hub
syncfusion-javascript-markdown-converter
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent on how to process untrusted Markdown data and render the result as HTML in a browser context.\n
- Ingestion points: User-provided Markdown strings passed to the
MarkdownConverter.toHtmlmethod as described inSKILL.mdandreferences/tohtml-api.md.\n - Boundary markers: The documentation does not suggest using delimiters or warnings to prevent the agent from following instructions embedded within the Markdown content being converted.\n
- Capability inventory: The skill demonstrates the capability to render output to the browser DOM using
innerHTMLinreferences/getting-started.mdandreferences/richtexteditor-integration.md.\n - Sanitization: The guides do not include instructions for sanitizing the generated HTML before rendering, which is a common vulnerability surface when handling user-authored content.
Audit Metadata