syncfusion-react-treeview
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is entirely composed of documentation and code examples for a React UI library. It contains no executable logic or malicious patterns.
- [EXTERNAL_DOWNLOADS]: The documentation references the installation of official Syncfusion Node.js packages, which are legitimate vendor resources consistent with the author.
- [INDIRECT_PROMPT_INJECTION]: The TreeView component handles hierarchical data, creating a surface for indirect prompt injection. 1. Ingestion points: Data is ingested via the dataSource property from local or remote sources. 2. Boundary markers: Not explicitly shown in code but recommended in best practices. 3. Capability inventory: Support for inline editing, drag-and-drop, and custom templates. 4. Sanitization: Documentation explicitly recommends sanitizing user input and provides code examples for doing so.
Audit Metadata