syncfusion-react-inputs
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as documentation for implementing UI components. It includes numerous safety markers (e.g., '🛑 STOP') instructing AI agents not to install packages or execute code without explicit user consent.
- [DATA_EXPOSURE_&_EXFILTRATION]: The skill provides explicit warnings against hardcoding sensitive data like JWT tokens and recommends secure session storage. It demonstrates best practices for managing authentication headers during file uploads.
- [INDIRECT_PROMPT_INJECTION]: While the components handled (TextBox, TextArea, Uploader) ingestion of untrusted data, the skill emphasizes the use of the built-in HTML sanitizer (enableHtmlSanitizer, enabled by default) to mitigate XSS and injection risks.
- [EXTERNAL_DOWNLOADS]: All referenced packages and URLs originate from official Syncfusion repositories or well-known development tools (e.g., npm, GitHub), posing no supply chain risk.
Audit Metadata