syncfusion-javascript-tab
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates rendering HTML content from potentially untrusted sources through the
items.contentproperty. \n - Ingestion points: The
contentproperty of tab items (seen inSKILL.mdandreferences/data-binding.md) allows for dynamic HTML strings or elements. \n - Boundary markers: The component provides a dedicated
enableHtmlSanitizerproperty to delimit and clean content, and the documentation includes explicit security warnings. \n - Capability inventory: The component renders content to the DOM using
appendToand manages lifecycle through methods likerefresh(seen inreferences/methods-reference.md). \n - Sanitization: HTML sanitization is enabled by default to mitigate XSS risks, and the documentation explicitly recommends additional sanitization using
DOMPurifyfor high-risk content. \n- [EXTERNAL_DOWNLOADS]: The skill references external resources necessary for component styling and demonstration. \n - Fetches Font Awesome icon styles from the Cloudflare CDN (
cdnjs.cloudflare.com). \n - Retrieves demonstration images from Syncfusion's official web domain (
ej2.syncfusion.com). \n - Uses a well-known OData service for data binding examples (
services.odata.org). \n - Provides instructions for cloning a development environment from the vendor-associated
SyncfusionExamplesGitHub repository.
Audit Metadata