skills/syncfusion/spreadsheet-editor-sdk-skills/syncfusion-javascript-spreadsheet-editor/Gen Agent Trust Hub
syncfusion-javascript-spreadsheet-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill demonstrates a strong security posture by including proactive guidance for developers. It features explicit 'SECURITY' warnings in its reference files (e.g.,
references/hyperlink.mdandreferences/data-binding.md) that instruct users to validate and sanitize URLs and remote endpoints before use. - [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion service endpoints (
document.syncfusion.com) for spreadsheet processing operations. As these belong to the vendor's known infrastructure and are required for the component's import/export features, they are considered safe. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for applications to ingest and process external data formats (XLSX, CSV, JSON). Although this represents a potential attack surface for indirect prompt injection at the application level, the skill mitigates this by providing developer-focused documentation on input validation and sanitization.
- Ingestion points: Data is loaded via the
dataSourceproperty inreferences/data-binding.mdand theopenmethod inreferences/import-export.md. - Boundary markers: The instructions do not define specific boundary markers for user data, as the skill is focused on generating implementation code rather than processing runtime data itself.
- Capability inventory: The skill possesses the capability to modify project files (via user-confirmed delivery options in
SKILL.md) and perform network operations using theDataManagerand standardfetchAPIs. - Sanitization: Sanitization guidance is explicitly provided in the reference documentation for both data binding and hyperlink insertion.
Audit Metadata