syncfusion-react-diagram

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs the installation of the @syncfusion/ej2-react-diagrams package and related themes from the public NPM registry (SKILL.md, references/getting-started.md). These are standard vendor resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data, creating an attack surface for indirect prompt injection. * Ingestion points: Data ingestion occurs via DataManager remote URLs (references/data-binding.md), loadDiagram for JSON, importFromVisio for Visio files, and loadDiagramFromMermaid for Mermaid syntax (references/serialization-and-export.md). * Boundary markers: The skill lacks delimiters or instructions to mark external data as untrusted or to ignore embedded instructions. * Capability inventory: The resulting React components can perform network-based CRUD sync (references/data-binding.md) and file exports (references/serialization-and-export.md). * Sanitization: No sanitization or validation logic is present in the provided code patterns.
  • [DYNAMIC_EXECUTION]: In references/serialization-and-export.md, the skill utilizes the loadDiagramFromMermaid method to dynamically build complex diagram layouts from external strings at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:20 AM
Security Audit — agent-trust-hub — syncfusion-react-diagram