syncfusion-react-menu
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents features for ingesting and rendering external data (API responses, JSON objects), which presents a potential indirect prompt injection and XSS surface.
- Ingestion points: Data is ingested through the
itemsproperty andfetchcalls as documented inreferences/data-binding.md. - Boundary markers: The component uses structured
MenuItemModelobjects, providing a schema-based separation between data fields and UI logic. - Capability inventory: The component can render HTML content and icons based on the provided data, which could be exploited if not sanitized.
- Sanitization: The
enableHtmlSanitizerproperty, documented inreferences/properties-and-configuration.md, is enabled by default to prevent malicious HTML/script injections in menu item text.
Audit Metadata