syncfusion-aspnetcore-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides functionality for binding the spreadsheet component to remote data sources and importing external files. This creates a surface where malicious instructions could be embedded in data processed by the agent.
  • Ingestion points: Data binding from APIs/JSON is documented in references/data-binding.md and file import operations are described in references/import-export.md.
  • Boundary markers: The manifest in SKILL.md requires the AI agent to explicitly ask the user for a delivery mode (sharing in chat, saving to a specific folder, or replacing project code) before generating and delivering code snippets.
  • Capability inventory: The generated code includes capabilities for network requests (via fetch or DataManager) and file system access for saving and opening workbooks.
  • Sanitization: The documentation includes specific security notes in references/hyperlink.md and references/import-export.md advising developers to validate and sanitize all URL inputs and external file sources to prevent malicious activity.
  • [EXTERNAL_DOWNLOADS]: The skill references Syncfusion's official CDN for CSS and JavaScript assets and directs users to install official NuGet packages for component functionality. These references target the vendor's own established infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:02 AM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-spreadsheet-editor