syncfusion-javascript-pdf-viewer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were detected. The skill follows best practices for AI agent development by providing authoritative reference material and strictly limiting the agent's output to documented APIs.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources, all of which originate from the official vendor (Syncfusion). These include a quickstart template from github.com/SyncfusionExamples/ej2-quickstart-webpack and library resources from cdn.syncfusion.com. These are trusted sources for the intended functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to inspect local workspace files (like package.json and tsconfig.json) to detect the project environment. While this constitutes a data ingestion surface, the risk is mitigated by the skill's extremely rigid feature support policy, which forbids the use of any undocumented or invented APIs, effectively preventing the agent from following instructions embedded in workspace files. Severity for this category remains low per standard classification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-javascript-pdf-viewer