syncfusion-javascript-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install official Syncfusion packages such as @syncfusion/ej2-spreadsheet and @syncfusion/ej2-data via standard package managers. It also references Syncfusion's official web service endpoints for spreadsheet file opening and saving (document.syncfusion.com), which are trusted vendor resources.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from external sources. 1. Ingestion points: The spreadsheet.open method in references/import-export.md and the dataSource property in references/data-binding.md. 2. Boundary markers: Absent. 3. Capability inventory: The skill can perform network operations via fetch and file operations through the spreadsheet component's save functionality. 4. Sanitization: No explicit sanitization of cell content is defined in the snippets, though a manual warning for hyperlink validation is included in references/hyperlink.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 09:59 AM