syncfusion-javascript-pdf-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were detected. The skill follows best practices for AI agent development by providing authoritative reference material and strictly limiting the agent's output to documented APIs.
- [EXTERNAL_DOWNLOADS]: The skill references several external resources, all of which originate from the official vendor (Syncfusion). These include a quickstart template from
github.com/SyncfusionExamples/ej2-quickstart-webpackand library resources fromcdn.syncfusion.com. These are trusted sources for the intended functionality. - [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to inspect local workspace files (like
package.jsonandtsconfig.json) to detect the project environment. While this constitutes a data ingestion surface, the risk is mitigated by the skill's extremely rigid feature support policy, which forbids the use of any undocumented or invented APIs, effectively preventing the agent from following instructions embedded in workspace files. Severity for this category remains low per standard classification.
Audit Metadata