syncfusion-react-license

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The skill instructs users to modify shell profiles to ensure environment variables are persistent across sessions.
  • Evidence: The skill suggests adding export SYNCFUSION_LICENSE="Your_License_Key_Here" to ~/.bash_profile in references/license-registration.md.
  • [COMMAND_EXECUTION]: The skill includes instructions to execute shell commands for licensing and maintenance.
  • Evidence: Instructions to run npx syncfusion-license activate for license registration and rm -rf node_modules/.cache for clearing build caches.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface where an agent might be instructed to process or register malicious license keys or modify system configurations based on untrusted input.
  • Ingestion points: The skill accepts a license key via environment variables or CLI input (SYNCFUSION_LICENSE).
  • Boundary markers: No specific delimiters or validation warnings are provided for the input key.
  • Capability inventory: The skill uses npx for command execution, rm for filesystem cleanup, and shell profile modification via echo.
  • Sanitization: The instructions do not specify sanitization or validation of the license key content before use.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 04:20 AM
Security Audit — agent-trust-hub — syncfusion-react-license