skills/syncfusion/javascript-ui-controls-skills/syncfusion-javascript-rich-text-editor/Gen Agent Trust Hub
syncfusion-javascript-rich-text-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides implementation guides for a well-known UI library using official Syncfusion packages. It emphasizes security by documenting the built-in HTML sanitizer and paste cleanup modules, which are active by default to mitigate cross-site scripting (XSS) risks. All external dependencies and service references are associated with trusted or well-known software vendors.\n- [INDIRECT_PROMPT_INJECTION]: The skill implements a rich text editor that processes external content, which constitutes a data ingestion surface. However, the documentation explicitly addresses sanitization to manage this risk.\n
- Ingestion points: Editor content properties, file uploads, and clipboard paste operations as described in content-operations.md and insert-image-media.md.\n
- Boundary markers: Employs an internal HTML sanitizer and configurable denied-tag lists in the PasteCleanup module.\n
- Capability inventory: Includes programmatic command execution, file storage operations on remote endpoints, and AI-driven content transformation.\n
- Sanitization: Provides the enableHtmlSanitizer property and dedicated sanitation events to filter malicious markup.
Audit Metadata