syncfusion-maui-pdf-viewer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for implementing a PDF viewer that ingests untrusted external files, which creates a standard surface for indirect prompt injection attacks.
  • Ingestion points: External PDF documents are loaded via the DocumentSource property and LoadDocument methods as shown in references/basic-sample.md and references/document-operations.md.
  • Boundary markers: The skill does not provide specific delimiters or instructions to the agent to ignore potentially malicious embedded content within the PDF files it processes.
  • Capability inventory: The code snippets provided grant the application capabilities to write to the local file system (SaveDocument in references/document-operations.md), print documents (PrintDocument in references/document-operations.md), and open external URLs in the system browser using Launcher.Default.OpenAsync (references/viewing.md).
  • Sanitization: No explicit sanitization or content validation logic is included in the reference materials for the data contained within the loaded PDF documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-maui-pdf-viewer