skills/syncfusion/spreadsheet-editor-sdk-skills/syncfusion-blazor-spreadsheet-editor/Gen Agent Trust Hub
syncfusion-blazor-spreadsheet-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides functionality for the agent to generate code that ingests untrusted data from external files and network sources, which establishes a surface for indirect prompt injection.
- Ingestion points:
references/open-save.md(loading JSON from remote URLs, local file system, and Google Drive);references/basic-sample.md(loading local Excel workbooks). - Boundary markers: Absent. The skill primarily handles binary data (byte arrays) or structured JSON data without specific delimiters to separate data from potential instructions.
- Capability inventory: The generated code includes file system read capabilities (
File.ReadAllBytes,File.ReadAllText) and network access viaHttpClientand the Google Drive API. - Sanitization: The skill explicitly includes security advisory comments in its code snippets (e.g., in
references/open-save.mdandreferences/hyperlink.md), directing users to implement URL allowlists, validate file ownership, and sanitize inputs to prevent injection attacks.
Audit Metadata