syncfusion-react-common
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for activating component licenses using the vendor-specific
npx syncfusion-license activateutility and setting environment variables for license keys. - [EXTERNAL_DOWNLOADS]: Includes standard package installation commands for Syncfusion React libraries and internationalization data (CLDR) from official NPM registries.
- [INDIRECT_PROMPT_INJECTION]: The skill provides UI components that ingest untrusted data, creating a potential surface for indirect prompt injection or XSS.
- Ingestion points:
dataSourceproperty inGridComponent(SKILL.md) andListViewComponent(references/globalization.md). - Boundary markers: Not explicitly shown in code snippets, but documentation references external security guidelines.
- Capability inventory: Components facilitate data rendering and UI interactions; no high-privilege system or network capabilities are exposed to the data ingestion surface.
- Sanitization: The documentation explicitly includes a "Security Best Practices" section in
references/advanced-features.mdlinking to Syncfusion's HTML sanitization documentation.
Audit Metadata