syncfusion-blazor-pdf-viewer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a strict feature support policy, instructing the agent to only use APIs explicitly listed in provided reference files. This is a best-practice reliability measure that reduces the risk of generating unsafe or hallucinated code.
  • [SAFE]: External resources such as NuGet packages (Syncfusion.Blazor.SfPdfViewer) and CDN links (cdn.syncfusion.com) originate from the verified vendor (Syncfusion) or well-known development ecosystems.
  • [SAFE]: Dockerfile examples in the deployment guide include standard commands for installing native dependencies (libgdiplus) required for PDF rendering on Linux environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it generates code based on user-provided descriptions. This is documented as a risk factor for transparency.
  • Ingestion points: User interaction prompts processed by the agent to determine UI requirements (e.g., in SKILL.md).
  • Boundary markers: The skill uses explicit instruction blocks and a 'Reference File Hierarchy' to bound agent behavior.
  • Capability inventory: Access to workspace inspection tools (file_search, read_file) and code generation for C# and Razor files.
  • Sanitization: Implementation of a 'Strict Mode' policy that prohibits the use of any API, method, or property not found in the provided local reference tables.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-blazor-pdf-viewer