syncfusion-blazor-smart-pdf-viewer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill generates code for an AI-powered PDF viewer that ingests external documents and user prompts. Maliciously crafted PDFs could contain hidden instructions aimed at manipulating the AI's output (e.g., during summarization or redaction).
  • Ingestion points: The DocumentPath property of the SfSmartPdfViewer and the Prompt property within AssistViewSettings are primary entry points for untrusted data.
  • Boundary markers: The generated code snippets do not include explicit prompt delimiters or "ignore embedded instructions" warnings when sending document content to the AI model.
  • Capability inventory: The skill facilitates document summarization, smart redaction, and form filling using Azure OpenAI or other chat clients.
  • Sanitization: There is no evidence of content sanitization or validation for the PDF data processed by the AI service.
  • [SAFE]: The skill enforces a "Strict Mode" policy for code generation, requiring the agent to validate every API, property, and method against provided reference tables. This prevents the generation of undocumented or invented code that could lead to unexpected behavior.
  • [SAFE]: All external dependencies (NuGet packages) and service references (Azure OpenAI, Ollama) originate from trusted or well-known organizations including Microsoft and Syncfusion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-blazor-smart-pdf-viewer