syncfusion-javascript-sankey

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the EJ2 JavaScript library from Syncfusion's official CDN (cdn.syncfusion.com) for use in web applications.
  • [EXTERNAL_DOWNLOADS]: References a quickstart template repository on Syncfusion's official GitHub organization (SyncfusionExamples/ej2-quickstart-webpack) for environment setup.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external flow data which could potentially contain malicious instructions.
  • Ingestion points: The nodes and links arrays defined in the skill and populated at runtime from external sources.
  • Boundary markers: The skill documentation explicitly instructs developers to use the validateSankeyData function to verify input collections before rendering.
  • Capability inventory: Component rendering, UI interaction handling (clicks, hovers), and data export (PNG, JPEG, SVG, PDF). It does not include arbitrary code execution or local file system write access.
  • Sanitization: Provides a comprehensive validation logic that checks for nonempty unique IDs, finite numeric values, and valid relationships between nodes and links.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-sankey