syncfusion-react-popups

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate collection of documentation and code samples for Syncfusion's React popup components. The instructions are technical and focused on library implementation.
  • [EXTERNAL_DOWNLOADS]: The skill references standard Syncfusion NPM packages including @syncfusion/ej2-react-popups, @syncfusion/ej2-base, @syncfusion/ej2-buttons, and @syncfusion/ej2-popups. These are official resources from a well-known vendor.
  • [INDIRECT_PROMPT_INJECTION]: While the documentation demonstrates how to fetch and render dynamic content from APIs (e.g., in references/tooltip-content.md and references/dialog-advanced-patterns.md), it explicitly warns developers about XSS risks. It provides evidence-based guidance on keeping the built-in HTML sanitizer enabled (enableHtmlSanitizer={true}) and performing manual character escaping for remote data.
  • [DYNAMIC_EXECUTION]: The skill uses conditional logic to optimize performance, such as checking navigator.deviceMemory to toggle animations. This is a legitimate feature toggle for low-end devices and does not gate any sensitive network or file operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:19 AM
Security Audit — agent-trust-hub — syncfusion-react-popups