syncfusion-angular-pdf-viewer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides APIs and documentation for extracting text and searching content within PDF documents. Since PDF files are untrusted external sources, their content could potentially contain malicious instructions aimed at influencing the agent's behavior during text processing tasks.
  • Ingestion points: PDF content is ingested via the extractText and textSearch modules documented in api-methods.md and text-search.md.
  • Boundary markers: The instructions do not specify delimiters or guidelines for the agent to separate document content from system instructions.
  • Capability inventory: The agent possesses capabilities to read local project files (read_file) and generate code snippets based on the project environment.
  • Sanitization: No sanitization or validation logic is prescribed for the data extracted from the PDF documents.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the official Syncfusion PDF Viewer package and references assets hosted on the vendor's CDN.
  • Evidence: The README.md suggests installing @syncfusion/ej2-angular-pdfviewer via npm and fetching library resources from cdn.syncfusion.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-angular-pdf-viewer