syncfusion-maui-image-editor
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides mechanisms to ingest external data through image sources and serialized state files, creating a surface for indirect prompt injection.
- Ingestion points: The
SfImageEditor.Sourceproperty (references/getting-started.md) and theSfImageEditor.Deserialize(stream)method (references/save-serialization.md). - Boundary markers: The documentation does not specify the use of delimiters or validation logic to distinguish data from instructions when processing external files.
- Capability inventory: The skill allows writing to the file system via the
Savemethod, accessing the camera viaMediaPicker, and reading image streams. - Sanitization: There is no evidence of sanitization for image metadata or serialized JSON content before it is processed by the agent or control.
- [DYNAMIC_EXECUTION]: The skill documents the
Deserializemethod inreferences/save-serialization.md, which reconstructs the editor's state (including annotations and transformations) from a JSON stream. This allows external data to dynamically influence the application's runtime state. - [COMMAND_EXECUTION]: The
references/getting-started.mdfile contains instructions for executing shell commands to install NuGet packages (dotnet add package Syncfusion.Maui.ImageEditor), which is a standard developer workflow but involves command-line interaction. - [DATA_EXFILTRATION]: The skill provides extensive capabilities for reading and writing data, including saving edited images to arbitrary local paths (e.g.,
D:\Syncfusion\Pictures) and accessing sensitive hardware like the camera and photo library. While these are documented features of the Syncfusion library, they could be leveraged by a malicious agent to harvest or move data.
Audit Metadata