syncfusion-javascript-notifications

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a pure documentation and reference guide for official Syncfusion UI components. It provides valid usage examples for front-end development using established libraries.
  • [SAFE]: All external resource references and package installations target legitimate Syncfusion infrastructure and the official NPM registry.
  • [PROMPT_INJECTION]: Several components (Toast, Message) accept untrusted data via the content and template properties (documented in references/toast-api.md and references/message-api.md). While the Toast component provides a beforeSanitizeHtml event to handle sanitization, the examples do not explicitly show input boundary markers. This constitutes a standard surface for indirect prompt injection, though the skill does not possess exploitable capabilities like network exfiltration or file system access.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 07:03 PM
Security Audit — agent-trust-hub — syncfusion-javascript-notifications