syncfusion-javascript-speech-to-text

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill serves as a legitimate developer guide for the Syncfusion JavaScript SpeechToText component, authored by Syncfusion Inc. All functionality described aligns with the primary purpose of a UI speech-to-text control.
  • [EXTERNAL_DOWNLOADS]: The documentation references official Syncfusion CSS assets hosted on cdn.syncfusion.com. These are well-known resources for this vendor and are used for component styling.
  • [DATA_EXFILTRATION]: The documentation explicitly addresses data privacy in its security section. It warns users that voice data is processed by third-party services (Google/Microsoft) and provides defensive code examples for redacting sensitive information like SSNs and credit card numbers from transcripts.
  • [INDIRECT_PROMPT_INJECTION]: As a speech-to-text tool, the component has a data ingestion surface (voice input). The skill mitigates this by documenting sanitization best practices and recommending explicit user consent and visual recording indicators. This is considered a safe implementation of the technology.
  • [NO_CODE]: The skill consists of documentation and code examples intended for developer use rather than executable scripts that perform operations during the skill's own loading or execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-speech-to-text