syncfusion-uwp-pdf-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install the 'Syncfusion.SfPdfViewer.UWP' package via NuGet, which is a legitimate library from a recognized vendor.
- [DYNAMIC_EXECUTION]: The 'references/utilities.md' file provides implementation examples for a custom renderer using P/Invoke ('DllImport') to call native functions. This includes the use of 'kernel32.dll!LoadLibrary' to dynamically load 'pdfium.dll' from the application's local folder at runtime, and 'unsafe' code blocks for pointer-based bitmap manipulation.
- [INDIRECT_PROMPT_INJECTION]: The skill provides capabilities for the agent to generate code that ingests and processes PDF files from untrusted sources. 1. Ingestion points: The 'LoadDocument' and 'LoadDocumentAsync' methods in 'references/viewing-pdf.md' and 'references/getting-started.md'. 2. Boundary markers: The skill includes explicit security warnings and provides code examples for validating hyperlinks. 3. Capability inventory: Includes file writing (SaveAsync), printing, and external navigation (Launcher.LaunchUriAsync). 4. Sanitization: Recommends and provides an implementation pattern for a domain whitelist ('IsUrlTrusted') to validate hyperlink targets.
Audit Metadata