syncfusion-react-data-manager

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from remote endpoints (OData, REST, GraphQL), which presents an attack surface for indirect prompt injection.
  • Ingestion points: Remote service URLs are defined via the url property in the DataManager configuration (SKILL.md, references/data-binding.md).
  • Boundary markers: The skill implements a 'MANDATORY HUMAN GATE' (references/adaptor-decision-gate.md) that forces the agent to stop and obtain explicit user confirmation before configuring a DataManager with a remote URL.
  • Capability inventory: The generated code performs network operations (executeQuery) and data mutations (insert, update, remove) against external services.
  • Sanitization: The skill provides comprehensive 'Critical Security Requirements' in SKILL.md and 'Security Warnings' in reference files, directing users to validate schemas, use HTTPS, and sanitize all third-party API responses.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @syncfusion/ej2-data package via npm. This is a standard, legitimate library provided by the skill's author for the stated functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:20 AM
Security Audit — agent-trust-hub — syncfusion-react-data-manager