syncfusion-react-pivot-table

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The documentation explains how to bind the PivotView component to remote data sources, which is a known ingestion surface for untrusted data. * Ingestion points: Data enters the component via the url and dataSource properties in dataSourceSettings, as shown in references/data-binding.md and references/connecting-to-databases.md. * Boundary markers: Present and highly prominent. The skill includes a 'CRITICAL SECURITY NOTICE' in SKILL.md and references/data-binding.md with detailed instructions on sanitization and validation. * Capability inventory: The component can fetch data from remote URLs using DataManager and render it in a complex UI grid. * Sanitization: The instructions explicitly recommend server-side data validation and client-side sanitization before binding.
  • [DYNAMIC_EXECUTION]: The calculated field feature documented in references/calculated-field.md utilizes mathematical formulas that can incorporate JavaScript Math object methods. While formulas are processed by the component's internal engine, this represents a dynamic logic surface. The skill provides remediation by documenting validation events like calculatedFieldCreate.
  • [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion repositories and package registries for installation and configuration. * Evidence: References to @syncfusion packages on npm and sample applications in the SyncfusionExamples GitHub repository (references/getting-started.md, references/connecting-to-data-source.md). These are author-owned resources and are documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:25 AM
Security Audit — agent-trust-hub — syncfusion-react-pivot-table