syncfusion-javascript-stepper

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The Stepper component processes data from the steps configuration array and the template property to render UI elements, which represents a potential injection surface if populated with untrusted data.
  • Ingestion points: steps (labels, text) and template (HTML string) defined in SKILL.md and references/steps-configuration.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are used when interpolating these values.
  • Capability inventory: The skill configures UI rendering and can persist state to browser storage via the enablePersistence property.
  • Sanitization: The documentation does not specify sanitization or escaping methods for data bound to templates or labels.
  • [EXTERNAL_DOWNLOADS]: Instructions are provided for installing the @syncfusion/ej2-navigations library and its dependencies from the official NPM registry, which are standard vendor resources.
  • [COMMAND_EXECUTION]: The getting started guide includes standard developer commands such as npm install, npm start, and a placeholder git clone command for setting up the development environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-stepper