syncfusion-react-ai-assistview
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documentation addresses the handling of untrusted data from AI services and user inputs. It provides appropriate security guidance, such as using input validation and sanitizing AI-generated content before rendering to prevent cross-site scripting (XSS). These are standard security practices for UI components of this nature.
- [CREDENTIALS_UNSAFE]: The documentation includes placeholders for API keys (e.g., 'Your_API_Key_Here') and explicitly warns developers against exposing credentials in client-side code, recommending the use of environment variables or backend proxies instead.
- [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion NPM packages and the well-known 'marked' library for markdown parsing. The example file upload endpoints target Syncfusion's official demo services, which are consistent with the vendor's own infrastructure.
Audit Metadata