skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-notifications/Gen Agent Trust Hub
syncfusion-javascript-notifications
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a pure documentation and reference guide for official Syncfusion UI components. It provides valid usage examples for front-end development using established libraries.
- [SAFE]: All external resource references and package installations target legitimate Syncfusion infrastructure and the official NPM registry.
- [PROMPT_INJECTION]: Several components (Toast, Message) accept untrusted data via the
contentandtemplateproperties (documented inreferences/toast-api.mdandreferences/message-api.md). While the Toast component provides abeforeSanitizeHtmlevent to handle sanitization, the examples do not explicitly show input boundary markers. This constitutes a standard surface for indirect prompt injection, though the skill does not possess exploitable capabilities like network exfiltration or file system access.
Audit Metadata