syncfusion-javascript-tab

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates rendering HTML content from potentially untrusted sources through the items.content property. \n
  • Ingestion points: The content property of tab items (seen in SKILL.md and references/data-binding.md) allows for dynamic HTML strings or elements. \n
  • Boundary markers: The component provides a dedicated enableHtmlSanitizer property to delimit and clean content, and the documentation includes explicit security warnings. \n
  • Capability inventory: The component renders content to the DOM using appendTo and manages lifecycle through methods like refresh (seen in references/methods-reference.md). \n
  • Sanitization: HTML sanitization is enabled by default to mitigate XSS risks, and the documentation explicitly recommends additional sanitization using DOMPurify for high-risk content. \n- [EXTERNAL_DOWNLOADS]: The skill references external resources necessary for component styling and demonstration. \n
  • Fetches Font Awesome icon styles from the Cloudflare CDN (cdnjs.cloudflare.com). \n
  • Retrieves demonstration images from Syncfusion's official web domain (ej2.syncfusion.com). \n
  • Uses a well-known OData service for data binding examples (services.odata.org). \n
  • Provides instructions for cloning a development environment from the vendor-associated SyncfusionExamples GitHub repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-tab