skills/syncfusion/pure-react-ui-components-skills/syncfusion-pure-react-scheduler/Gen Agent Trust Hub
syncfusion-pure-react-scheduler
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for registering license keys using the
npx syncfusion-react-license activatecommand, which is a standard procedure for this vendor's components to remove trial watermarks. - [EXTERNAL_DOWNLOADS]: The skill fetches sample event data and localized culture data from official Syncfusion domains, such as
ej2services.syncfusion.comandservices.syncfusion.com. These are recognized as legitimate vendor resources for functional demonstrations. - [INDIRECT_PROMPT_INJECTION]: The skill documents a data-driven component that processes external input, creating a potential attack surface for indirect prompt injection.
- Ingestion points: Event data is ingested through the
eventSettings.dataSourceproperty as described inreferences/events-data.mdandreferences/load-on-demand.md. - Boundary markers: The skill does not explicitly define delimiters or instructions for the agent to ignore potentially malicious embedded content within the event objects.
- Capability inventory: The component supports network requests, state updates, and custom template rendering (
eventTemplate) during the event lifecycle (onDataChangeStartandonDataChangeComplete). - Sanitization: There are no instructions in the documentation regarding the sanitization of external data strings before they are processed or rendered by the component.
Audit Metadata