syncfusion-javascript-sparkline
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the EJ2 Charts library via npm and references official Syncfusion CDN assets for global JavaScript implementation. These resources originate from the vendor and are used for their intended purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent on how to map external data sources to Sparkline components, where values are interpolated into tooltip and data label templates using placeholders like
${x}and${y}. - Ingestion points: Untrusted data enters the component via the
dataSourceproperty, as shown inSKILL.mdand multiple reference files. - Boundary markers: There are no explicit instructions or delimiters used to prevent the agent or the component from interpreting data content as instructions.
- Capability inventory: The component renders SVG graphics and HTML-based tooltips and labels.
- Sanitization: The skill does not provide specific guidance on sanitizing or validating the input data before it is rendered by the visualization component.
Audit Metadata