syncfusion-javascript-treeview

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides detailed implementation guides and API documentation for a legitimate UI component library. The instructions and code examples focus on standard library usage for data binding, navigation, and customization.\n- [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion demonstration services (ej2services.syncfusion.com) and standard OData endpoints (services.odata.org) for data binding examples. It also specifies the use of official CSS themes hosted on public CDNs for the @syncfusion organization. These are recognized vendor resources and well-known services.\n- [INDIRECT_PROMPT_INJECTION]: The component possesses an attack surface as it is designed to ingest and render hierarchical data from external sources, potentially including raw HTML through the 'disableHtmlEncode' property. However, the documentation correctly identifies the 'enableHtmlSanitizer' property as a primary security control and encourages its use to mitigate potential injection risks from untrusted data sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-treeview