syncfusion-javascript-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill demonstrates a strong security posture by including proactive guidance for developers. It features explicit 'SECURITY' warnings in its reference files (e.g., references/hyperlink.md and references/data-binding.md) that instruct users to validate and sanitize URLs and remote endpoints before use.
  • [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion service endpoints (document.syncfusion.com) for spreadsheet processing operations. As these belong to the vendor's known infrastructure and are required for the component's import/export features, they are considered safe.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for applications to ingest and process external data formats (XLSX, CSV, JSON). Although this represents a potential attack surface for indirect prompt injection at the application level, the skill mitigates this by providing developer-focused documentation on input validation and sanitization.
  • Ingestion points: Data is loaded via the dataSource property in references/data-binding.md and the open method in references/import-export.md.
  • Boundary markers: The instructions do not define specific boundary markers for user data, as the skill is focused on generating implementation code rather than processing runtime data itself.
  • Capability inventory: The skill possesses the capability to modify project files (via user-confirmed delivery options in SKILL.md) and perform network operations using the DataManager and standard fetch APIs.
  • Sanitization: Sanitization guidance is explicitly provided in the reference documentation for both data binding and hyperlink insertion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:02 AM
Security Audit — agent-trust-hub — syncfusion-javascript-spreadsheet-editor