syncfusion-blazor-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides functionality for the agent to generate code that ingests untrusted data from external files and network sources, which establishes a surface for indirect prompt injection.
  • Ingestion points: references/open-save.md (loading JSON from remote URLs, local file system, and Google Drive); references/basic-sample.md (loading local Excel workbooks).
  • Boundary markers: Absent. The skill primarily handles binary data (byte arrays) or structured JSON data without specific delimiters to separate data from potential instructions.
  • Capability inventory: The generated code includes file system read capabilities (File.ReadAllBytes, File.ReadAllText) and network access via HttpClient and the Google Drive API.
  • Sanitization: The skill explicitly includes security advisory comments in its code snippets (e.g., in references/open-save.md and references/hyperlink.md), directing users to implement URL allowlists, validate file ownership, and sanitize inputs to prevent injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:02 AM
Security Audit — agent-trust-hub — syncfusion-blazor-spreadsheet-editor