syncfusion-javascript-ribbon
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the implementation of UI components that accept HTML templates and content strings, creating an indirect prompt injection surface.\n
- Ingestion points: Component configuration objects in SKILL.md and reference files like backstage.md and tooltip-and-help.md.\n
- Boundary markers: None identified in the documentation snippets.\n
- Capability inventory: JavaScript event handling and Ribbon API methods as detailed in events-and-api.md.\n
- Sanitization: Not addressed in the provided documentation.
Audit Metadata