syncfusion-react-menu

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents features for ingesting and rendering external data (API responses, JSON objects), which presents a potential indirect prompt injection and XSS surface.
  • Ingestion points: Data is ingested through the items property and fetch calls as documented in references/data-binding.md.
  • Boundary markers: The component uses structured MenuItemModel objects, providing a schema-based separation between data fields and UI logic.
  • Capability inventory: The component can render HTML content and icons based on the provided data, which could be exploited if not sanitized.
  • Sanitization: The enableHtmlSanitizer property, documented in references/properties-and-configuration.md, is enabled by default to prevent malicious HTML/script injections in menu item text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:19 AM
Security Audit — agent-trust-hub — syncfusion-react-menu