syncfusion-vue-pdf-viewer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by Syncfusion Inc and exclusively references official vendor resources, including the @syncfusion/ej2-vue-pdfviewer package and assets hosted on cdn.syncfusion.com. These are recognized as trusted vendor resources.
  • [SAFE]: Instructions in SKILL.md implement a 'Strict Mode' policy, mandating that the agent only uses APIs and properties explicitly documented in the provided reference files. This reduces the risk of generating insecure or unsupported code patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses file_search and read_file to inspect local project files (package.json, App.vue, etc.) to determine the Vue version and project structure. While this is an ingestion of untrusted data, the risk is mitigated as the data is used solely for configuration detection and the skill lacks dangerous capabilities such as arbitrary network exfiltration of that data.
  • [EXTERNAL_DOWNLOADS]: The skill documentation recommends downloading WebAssembly resources and CSS from official Syncfusion NPM packages and CDNs. These are standard development practices for this component and are considered safe under the vendor trust rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:00 AM
Security Audit — agent-trust-hub — syncfusion-vue-pdf-viewer