syncfusion-maui-combobox
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an implementation for AI-powered filtering that introduces an attack surface for indirect prompt injection through user-supplied search queries.\n
- Ingestion points: User input enters the application context via the
filterInfo.Textparameter within theGetMatchingIndexesmethod of theAIComboBoxFilterBehaviorclass (File:references/ai-smart-searching.md).\n - Boundary markers: The provided code snippets do not include explicit delimiters or instructions to the model to ignore potential malicious content embedded in the search string.\n
- Capability inventory: The skill is configured to use the
Azure.AI.OpenAIlibrary, which performs network operations to external AI endpoints for embedding generation.\n - Sanitization: The implementation lacks evidence of input sanitization or validation for the search text before it is transmitted to the remote embedding service.\n- [DATA_EXFILTRATION]: The semantic search functionality transmits user-entered text to a remote Azure OpenAI endpoint to generate embeddings. While this operation targets a well-known service and is a core part of the described feature, users should be aware of the external data flow.\n- [EXTERNAL_DOWNLOADS]: The documentation guides the installation of various NuGet packages, including
Azure.AI.OpenAIandMicrosoft.Extensions.Http. These resources originate from well-known and trusted technology organizations.
Audit Metadata