syncfusion-javascript-stepper
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The Stepper component processes data from the
stepsconfiguration array and thetemplateproperty to render UI elements, which represents a potential injection surface if populated with untrusted data. - Ingestion points:
steps(labels, text) andtemplate(HTML string) defined inSKILL.mdandreferences/steps-configuration.md. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are used when interpolating these values.
- Capability inventory: The skill configures UI rendering and can persist state to browser storage via the
enablePersistenceproperty. - Sanitization: The documentation does not specify sanitization or escaping methods for data bound to templates or labels.
- [EXTERNAL_DOWNLOADS]: Instructions are provided for installing the
@syncfusion/ej2-navigationslibrary and its dependencies from the official NPM registry, which are standard vendor resources. - [COMMAND_EXECUTION]: The getting started guide includes standard developer commands such as
npm install,npm start, and a placeholdergit clonecommand for setting up the development environment.
Audit Metadata