syncfusion-react-popups
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate collection of documentation and code samples for Syncfusion's React popup components. The instructions are technical and focused on library implementation.
- [EXTERNAL_DOWNLOADS]: The skill references standard Syncfusion NPM packages including
@syncfusion/ej2-react-popups,@syncfusion/ej2-base,@syncfusion/ej2-buttons, and@syncfusion/ej2-popups. These are official resources from a well-known vendor. - [INDIRECT_PROMPT_INJECTION]: While the documentation demonstrates how to fetch and render dynamic content from APIs (e.g., in
references/tooltip-content.mdandreferences/dialog-advanced-patterns.md), it explicitly warns developers about XSS risks. It provides evidence-based guidance on keeping the built-in HTML sanitizer enabled (enableHtmlSanitizer={true}) and performing manual character escaping for remote data. - [DYNAMIC_EXECUTION]: The skill uses conditional logic to optimize performance, such as checking
navigator.deviceMemoryto toggle animations. This is a legitimate feature toggle for low-end devices and does not gate any sensitive network or file operations.
Audit Metadata