syncfusion-react-chat-ui

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the display of user-generated chat messages, which constitutes an ingestion point for untrusted data.
  • Ingestion points: references/message-management.md (via addMessage and MessageDirective).
  • Boundary markers: The component does not implement internal boundary markers, but the documentation provides clear guidance on developer-side implementation.
  • Capability inventory: Component is limited to UI rendering of chat content.
  • Sanitization: The documentation explicitly instructs users to use DOMPurify to sanitize content after markdown parsing to prevent XSS attacks.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references external resources for package installation and file upload services.
  • Evidence: The skill utilizes standard NPM installation commands for @syncfusion/ej2-react-interactive-chat and provides example endpoints targeting services.syncfusion.com for file attachment functionality. These resources are official vendor assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:19 AM
Security Audit — agent-trust-hub — syncfusion-react-chat-ui