syncfusion-react-heatmap
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a component that ingests data for visualization. Ingestion points: The
dataSourceproperty accepts arrays or JSON objects as seen inSKILL.mdandreferences/data-binding.md. Boundary markers: The component provides anenableHtmlSanitizerproperty to handle untrusted content, as documented inreferences/api-reference.md. Capability inventory: The component performs UI rendering and handles interactive events likecellClickandcellRenderas described inreferences/interaction-and-selection.md. Sanitization: The library includes built-in HTML sanitization capabilities to mitigate risks from untrusted data. - [EXTERNAL_DOWNLOADS]: The documentation instructs the user to install legitimate software packages (e.g.,
@syncfusion/ej2-react-heatmap) from the official NPM registry, which is standard practice for this library (evidence inreferences/getting-started.md).
Audit Metadata