skills/syncfusion/spreadsheet-editor-sdk-skills/syncfusion-react-spreadsheet-editor/Gen Agent Trust Hub
syncfusion-react-spreadsheet-editor
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted external data (Excel/CSV files) and remote data binding, which introduces a potential surface for indirect prompt injection.
- Ingestion points: Data is ingested via the
open()method (import-export.md) andDataManagerfor remote API binding (data-binding.md). - Boundary markers: While code snippets do not feature explicit delimiters, the SKILL.md manifest requires the agent to provide guidance on input validation.
- Capability inventory: The skill enables formula execution, network requests to server endpoints for saving/opening files, and file exports.
- Sanitization: The SKILL.md 'Security' section mandates that generated code includes guidance to validate/whitelist URLs and sanitize uploads.
- [EXTERNAL_DOWNLOADS]: The skill references and requires official Node.js packages and CSS themes from the vendor.
- Packages: Includes
@syncfusion/ej2-react-spreadsheet,@syncfusion/ej2-tailwind3-theme, and related utility libraries. - Context: These are standard vendor-owned resources used for the skill's primary purpose.
- [COMMAND_EXECUTION]: The skill describes a delivery mode involving file replacement within a user project.
- Evidence: SKILL.md defines a workflow to replace code in specific project files (Option 1).
- Safeguards: Explicit rules require the agent to validate the project path, verify the existence of a React project (package.json), and obtain affirmative user permission before making any changes.
Audit Metadata