syncfusion-react-pivot-table
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The documentation explains how to bind the PivotView component to remote data sources, which is a known ingestion surface for untrusted data. * Ingestion points: Data enters the component via the
urlanddataSourceproperties indataSourceSettings, as shown inreferences/data-binding.mdandreferences/connecting-to-databases.md. * Boundary markers: Present and highly prominent. The skill includes a 'CRITICAL SECURITY NOTICE' inSKILL.mdandreferences/data-binding.mdwith detailed instructions on sanitization and validation. * Capability inventory: The component can fetch data from remote URLs usingDataManagerand render it in a complex UI grid. * Sanitization: The instructions explicitly recommend server-side data validation and client-side sanitization before binding. - [DYNAMIC_EXECUTION]: The calculated field feature documented in
references/calculated-field.mdutilizes mathematical formulas that can incorporate JavaScript Math object methods. While formulas are processed by the component's internal engine, this represents a dynamic logic surface. The skill provides remediation by documenting validation events likecalculatedFieldCreate. - [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion repositories and package registries for installation and configuration. * Evidence: References to
@syncfusionpackages on npm and sample applications in theSyncfusionExamplesGitHub repository (references/getting-started.md,references/connecting-to-data-source.md). These are author-owned resources and are documented neutrally.
Audit Metadata