syncfusion-maui-chat
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation directs users to install the
Syncfusion.Maui.Chatpackage from the NuGet registry. This is a standard procedure for integrating third-party UI components in .NET development and does not represent a security risk when using established vendors. - [COMMAND_EXECUTION]: The
SKILL.mdquick start guide includes thedotnet add packagecommand. This is the standard command-line interface method for adding dependencies to a .NET project. - [INDIRECT_PROMPT_INJECTION]: The skill implements a user interface for displaying messages which, by design, ingests and processes content from external and potentially untrusted sources (e.g., other chat participants or automated bots). This establishes a vulnerability surface for indirect prompt injection if the agent interprets instructions embedded within the chat history.
- Ingestion points: The
Messagescollection (documented inSKILL.md) and theItemsSourceproperty (documented inreferences/data-binding.md) serve as the entry points for untrusted data into the agent's view. - Boundary markers: There is no specific mention of using delimiters or clear instructions to the agent to treat chat content as data rather than instructions.
- Capability inventory: The skill provides a range of interactive event handlers for message submission, card interaction, and suggestion selection (
references/events.md), which could be triggered by interactions influenced by injected content. - Sanitization: The provided documentation does not detail any mechanisms for escaping or sanitizing the content of messages before they are rendered or processed by the agent.
Audit Metadata