syncfusion-react-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted external data (Excel/CSV files) and remote data binding, which introduces a potential surface for indirect prompt injection.
  • Ingestion points: Data is ingested via the open() method (import-export.md) and DataManager for remote API binding (data-binding.md).
  • Boundary markers: While code snippets do not feature explicit delimiters, the SKILL.md manifest requires the agent to provide guidance on input validation.
  • Capability inventory: The skill enables formula execution, network requests to server endpoints for saving/opening files, and file exports.
  • Sanitization: The SKILL.md 'Security' section mandates that generated code includes guidance to validate/whitelist URLs and sanitize uploads.
  • [EXTERNAL_DOWNLOADS]: The skill references and requires official Node.js packages and CSS themes from the vendor.
  • Packages: Includes @syncfusion/ej2-react-spreadsheet, @syncfusion/ej2-tailwind3-theme, and related utility libraries.
  • Context: These are standard vendor-owned resources used for the skill's primary purpose.
  • [COMMAND_EXECUTION]: The skill describes a delivery mode involving file replacement within a user project.
  • Evidence: SKILL.md defines a workflow to replace code in specific project files (Option 1).
  • Safeguards: Explicit rules require the agent to validate the project path, verify the existence of a React project (package.json), and obtain affirmative user permission before making any changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:27 PM
Security Audit — agent-trust-hub — syncfusion-react-spreadsheet-editor