syncfusion-react-splitter
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the installation of official Syncfusion packages (@syncfusion/ej2-react-layouts, @syncfusion/ej2-base) via npm, which are standard dependencies for the React Splitter component.
- [INDIRECT_PROMPT_INJECTION]: The component supports rendering HTML content in panes (PaneDirective), which represents an ingestion point for potentially untrusted data. The skill correctly mitigates this risk by documenting the built-in HTML sanitizer, which is enabled by default, and providing guidance on how to audit security-sensitive operations via the beforeSanitizeHtml event.
- [PERSISTENCE]: The documentation includes patterns for saving and restoring layout states using localStorage. This is used exclusively for preserving user UI preferences, such as pane sizes and visibility, and does not exhibit malicious behavior or unauthorized system access.
Audit Metadata