syncfusion-javascript-sankey
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the EJ2 JavaScript library from Syncfusion's official CDN (cdn.syncfusion.com) for use in web applications.
- [EXTERNAL_DOWNLOADS]: References a quickstart template repository on Syncfusion's official GitHub organization (SyncfusionExamples/ej2-quickstart-webpack) for environment setup.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external flow data which could potentially contain malicious instructions.
- Ingestion points: The
nodesandlinksarrays defined in the skill and populated at runtime from external sources. - Boundary markers: The skill documentation explicitly instructs developers to use the
validateSankeyDatafunction to verify input collections before rendering. - Capability inventory: Component rendering, UI interaction handling (clicks, hovers), and data export (PNG, JPEG, SVG, PDF). It does not include arbitrary code execution or local file system write access.
- Sanitization: Provides a comprehensive validation logic that checks for nonempty unique IDs, finite numeric values, and valid relationships between nodes and links.
Audit Metadata