syncfusion-react-scheduler

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of official Node.js packages provided by the vendor Syncfusion (e.g., @syncfusion/ej2-react-schedule, @syncfusion/ej2-tailwind3-theme, and @syncfusion/ej2-cldr-data). These are legitimate vendor-owned resources required for the component's functionality.
  • [CREDENTIALS_UNSAFE]: The documentation includes integration examples for Google Calendar using the placeholder <GOOGLE_API_KEY>. Per security guidelines, the use of explicit placeholders for configuration values is a safe practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill explicitly defines security constraints for untrusted data handling, instructing the agent to treat all event fields (Subject, Description, etc.) as display-only strings and to ignore any embedded commands. This demonstrates a proactive approach to mitigating injection risks from third-party data sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:45 AM
Security Audit — agent-trust-hub — syncfusion-react-scheduler