syncfusion-blazor-pdf-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a strict feature support policy, instructing the agent to only use APIs explicitly listed in provided reference files. This is a best-practice reliability measure that reduces the risk of generating unsafe or hallucinated code.
- [SAFE]: External resources such as NuGet packages (Syncfusion.Blazor.SfPdfViewer) and CDN links (cdn.syncfusion.com) originate from the verified vendor (Syncfusion) or well-known development ecosystems.
- [SAFE]: Dockerfile examples in the deployment guide include standard commands for installing native dependencies (libgdiplus) required for PDF rendering on Linux environments.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it generates code based on user-provided descriptions. This is documented as a risk factor for transparency.
- Ingestion points: User interaction prompts processed by the agent to determine UI requirements (e.g., in
SKILL.md). - Boundary markers: The skill uses explicit instruction blocks and a 'Reference File Hierarchy' to bound agent behavior.
- Capability inventory: Access to workspace inspection tools (
file_search,read_file) and code generation for C# and Razor files. - Sanitization: Implementation of a 'Strict Mode' policy that prohibits the use of any API, method, or property not found in the provided local reference tables.
Audit Metadata