syncfusion-react-data-manager
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from remote endpoints (OData, REST, GraphQL), which presents an attack surface for indirect prompt injection.
- Ingestion points: Remote service URLs are defined via the
urlproperty in the DataManager configuration (SKILL.md, references/data-binding.md). - Boundary markers: The skill implements a 'MANDATORY HUMAN GATE' (references/adaptor-decision-gate.md) that forces the agent to stop and obtain explicit user confirmation before configuring a DataManager with a remote URL.
- Capability inventory: The generated code performs network operations (
executeQuery) and data mutations (insert,update,remove) against external services. - Sanitization: The skill provides comprehensive 'Critical Security Requirements' in SKILL.md and 'Security Warnings' in reference files, directing users to validate schemas, use HTTPS, and sanitize all third-party API responses.
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@syncfusion/ej2-datapackage via npm. This is a standard, legitimate library provided by the skill's author for the stated functionality.
Audit Metadata