syncfusion-react-license
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The skill instructs users to modify shell profiles to ensure environment variables are persistent across sessions.
- Evidence: The skill suggests adding
export SYNCFUSION_LICENSE="Your_License_Key_Here"to~/.bash_profileinreferences/license-registration.md. - [COMMAND_EXECUTION]: The skill includes instructions to execute shell commands for licensing and maintenance.
- Evidence: Instructions to run
npx syncfusion-license activatefor license registration andrm -rf node_modules/.cachefor clearing build caches. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface where an agent might be instructed to process or register malicious license keys or modify system configurations based on untrusted input.
- Ingestion points: The skill accepts a license key via environment variables or CLI input (
SYNCFUSION_LICENSE). - Boundary markers: No specific delimiters or validation warnings are provided for the input key.
- Capability inventory: The skill uses
npxfor command execution,rmfor filesystem cleanup, and shell profile modification viaecho. - Sanitization: The instructions do not specify sanitization or validation of the license key content before use.
Audit Metadata