syncfusion-vue-pdf-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by Syncfusion Inc and exclusively references official vendor resources, including the
@syncfusion/ej2-vue-pdfviewerpackage and assets hosted oncdn.syncfusion.com. These are recognized as trusted vendor resources. - [SAFE]: Instructions in
SKILL.mdimplement a 'Strict Mode' policy, mandating that the agent only uses APIs and properties explicitly documented in the provided reference files. This reduces the risk of generating insecure or unsupported code patterns. - [INDIRECT_PROMPT_INJECTION]: The skill uses
file_searchandread_fileto inspect local project files (package.json,App.vue, etc.) to determine the Vue version and project structure. While this is an ingestion of untrusted data, the risk is mitigated as the data is used solely for configuration detection and the skill lacks dangerous capabilities such as arbitrary network exfiltration of that data. - [EXTERNAL_DOWNLOADS]: The skill documentation recommends downloading WebAssembly resources and CSS from official Syncfusion NPM packages and CDNs. These are standard development practices for this component and are considered safe under the vendor trust rules.
Audit Metadata