syncfusion-maui-combobox

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an implementation for AI-powered filtering that introduces an attack surface for indirect prompt injection through user-supplied search queries.\n
  • Ingestion points: User input enters the application context via the filterInfo.Text parameter within the GetMatchingIndexes method of the AIComboBoxFilterBehavior class (File: references/ai-smart-searching.md).\n
  • Boundary markers: The provided code snippets do not include explicit delimiters or instructions to the model to ignore potential malicious content embedded in the search string.\n
  • Capability inventory: The skill is configured to use the Azure.AI.OpenAI library, which performs network operations to external AI endpoints for embedding generation.\n
  • Sanitization: The implementation lacks evidence of input sanitization or validation for the search text before it is transmitted to the remote embedding service.\n- [DATA_EXFILTRATION]: The semantic search functionality transmits user-entered text to a remote Azure OpenAI endpoint to generate embeddings. While this operation targets a well-known service and is a core part of the described feature, users should be aware of the external data flow.\n- [EXTERNAL_DOWNLOADS]: The documentation guides the installation of various NuGet packages, including Azure.AI.OpenAI and Microsoft.Extensions.Http. These resources originate from well-known and trusted technology organizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 11:31 AM
Security Audit — agent-trust-hub — syncfusion-maui-combobox