syncfusion-javascript-treemap

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The TreeMap component processes untrusted data through the dataSource property, creating a potential risk of cross-site scripting (XSS) or indirect prompt injection if malicious content is included in labels or templates. Ingestion points: Data enters the component via the dataSource property as described in SKILL.md and references/data-binding.md. Boundary markers: No specific delimiters or safety warnings for data content are provided. Capability inventory: The component can render custom HTML templates, interact with the DOM via appendTo, and export processed data to Base64 strings. Sanitization: A built-in sanitizer is available through the enableHtmlSanitizer property, but it is documented as false by default in references/api-reference.md.
  • [DATA_EXFILTRATION]: The component provides an export() method that can return the rendered visualization as a Base64-encoded string. While intended for image previews, this capability represents a potential path for data exposure or exfiltration from the agent's environment.
  • [EXTERNAL_DOWNLOADS]: The documentation references the installation of the @syncfusion/ej2-treemap package from npm and provides examples using the official Syncfusion CDN at cdn.syncfusion.com. These references target legitimate vendor-controlled infrastructure and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-treemap