syncfusion-pure-react-scheduler

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for registering license keys using the npx syncfusion-react-license activate command, which is a standard procedure for this vendor's components to remove trial watermarks.
  • [EXTERNAL_DOWNLOADS]: The skill fetches sample event data and localized culture data from official Syncfusion domains, such as ej2services.syncfusion.com and services.syncfusion.com. These are recognized as legitimate vendor resources for functional demonstrations.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a data-driven component that processes external input, creating a potential attack surface for indirect prompt injection.
  • Ingestion points: Event data is ingested through the eventSettings.dataSource property as described in references/events-data.md and references/load-on-demand.md.
  • Boundary markers: The skill does not explicitly define delimiters or instructions for the agent to ignore potentially malicious embedded content within the event objects.
  • Capability inventory: The component supports network requests, state updates, and custom template rendering (eventTemplate) during the event lifecycle (onDataChangeStart and onDataChangeComplete).
  • Sanitization: There are no instructions in the documentation regarding the sanitization of external data strings before they are processed or rendered by the component.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 02:59 PM
Security Audit — agent-trust-hub — syncfusion-pure-react-scheduler