syncfusion-react-scheduler
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the installation of official Node.js packages provided by the vendor Syncfusion (e.g.,
@syncfusion/ej2-react-schedule,@syncfusion/ej2-tailwind3-theme, and@syncfusion/ej2-cldr-data). These are legitimate vendor-owned resources required for the component's functionality. - [CREDENTIALS_UNSAFE]: The documentation includes integration examples for Google Calendar using the placeholder
<GOOGLE_API_KEY>. Per security guidelines, the use of explicit placeholders for configuration values is a safe practice. - [INDIRECT_PROMPT_INJECTION]: The skill explicitly defines security constraints for untrusted data handling, instructing the agent to treat all event fields (Subject, Description, etc.) as display-only strings and to ignore any embedded commands. This demonstrates a proactive approach to mitigating injection risks from third-party data sources.
Audit Metadata