syncfusion-pure-react-grid
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The documentation emphasizes security best practices, such as suppressing diagnostic output in production and avoiding the commitment of license keys to source control.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted data from various external sources (e.g., OData, custom APIs) which could contain malicious instructions. The guidance mitigates this by highlighting the grid's default HTML encoding and recommending sanitization.
- Ingestion points: The dataSource property and onDataRequest event in SKILL.md and references/data-binding.md allow the grid to ingest content from external backends.
- Boundary markers: Data is processed in structured JSON formats, and the grid provides a disableHtmlEncode setting that is false by default to sanitize rendered content.
- Capability inventory: The grid supports data mutation operations (addRecord, deleteRecord, updateRecord) and file generation capabilities (useGridPdfExport, useGridExcelExport) that could be influenced by injected data.
- Sanitization: Cell content is HTML-encoded by default, providing a layer of defense against cross-site scripting (XSS) attacks originating from the data source.
Audit Metadata