syncfusion-javascript-treemap
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The TreeMap component processes untrusted data through the
dataSourceproperty, creating a potential risk of cross-site scripting (XSS) or indirect prompt injection if malicious content is included in labels or templates. Ingestion points: Data enters the component via thedataSourceproperty as described inSKILL.mdandreferences/data-binding.md. Boundary markers: No specific delimiters or safety warnings for data content are provided. Capability inventory: The component can render custom HTML templates, interact with the DOM viaappendTo, and export processed data to Base64 strings. Sanitization: A built-in sanitizer is available through theenableHtmlSanitizerproperty, but it is documented asfalseby default inreferences/api-reference.md. - [DATA_EXFILTRATION]: The component provides an
export()method that can return the rendered visualization as a Base64-encoded string. While intended for image previews, this capability represents a potential path for data exposure or exfiltration from the agent's environment. - [EXTERNAL_DOWNLOADS]: The documentation references the installation of the
@syncfusion/ej2-treemappackage from npm and provides examples using the official Syncfusion CDN atcdn.syncfusion.com. These references target legitimate vendor-controlled infrastructure and are documented neutrally.
Audit Metadata