syncfusion-react-common

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions for activating component licenses using the vendor-specific npx syncfusion-license activate utility and setting environment variables for license keys.
  • [EXTERNAL_DOWNLOADS]: Includes standard package installation commands for Syncfusion React libraries and internationalization data (CLDR) from official NPM registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides UI components that ingest untrusted data, creating a potential surface for indirect prompt injection or XSS.
  • Ingestion points: dataSource property in GridComponent (SKILL.md) and ListViewComponent (references/globalization.md).
  • Boundary markers: Not explicitly shown in code snippets, but documentation references external security guidelines.
  • Capability inventory: Components facilitate data rendering and UI interactions; no high-privilege system or network capabilities are exposed to the data ingestion surface.
  • Sanitization: The documentation explicitly includes a "Security Best Practices" section in references/advanced-features.md linking to Syncfusion's HTML sanitization documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:20 AM
Security Audit — agent-trust-hub — syncfusion-react-common