skills/syncfusion/spreadsheet-editor-sdk-skills/syncfusion-aspnetcore-spreadsheet-editor/Gen Agent Trust Hub
syncfusion-aspnetcore-spreadsheet-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides functionality for binding the spreadsheet component to remote data sources and importing external files. This creates a surface where malicious instructions could be embedded in data processed by the agent.
- Ingestion points: Data binding from APIs/JSON is documented in
references/data-binding.mdand file import operations are described inreferences/import-export.md. - Boundary markers: The manifest in
SKILL.mdrequires the AI agent to explicitly ask the user for a delivery mode (sharing in chat, saving to a specific folder, or replacing project code) before generating and delivering code snippets. - Capability inventory: The generated code includes capabilities for network requests (via
fetchorDataManager) and file system access for saving and opening workbooks. - Sanitization: The documentation includes specific security notes in
references/hyperlink.mdandreferences/import-export.mdadvising developers to validate and sanitize all URL inputs and external file sources to prevent malicious activity. - [EXTERNAL_DOWNLOADS]: The skill references Syncfusion's official CDN for CSS and JavaScript assets and directs users to install official NuGet packages for component functionality. These references target the vendor's own established infrastructure.
Audit Metadata