syncfusion-uwp-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses reflection to access internal property states and supports the registration of custom formula logic. These are standard developer extensibility features within the Syncfusion SDK.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface to open and process spreadsheet files, which is a known attack surface for indirect prompt injection. 1. Ingestion points: File opening methods in 'gettingstarted.md'. 2. Boundary markers: The skill instructions require the agent to pause for user confirmation before writing files. 3. Capability inventory: Generates and applies C# code to user projects. 4. Sanitization: Utilizes standard library parsers.
  • [COMMAND_EXECUTION]: The documentation includes standard NuGet CLI commands for package installation, which is a routine and safe development operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:02 AM
Security Audit — agent-trust-hub — syncfusion-uwp-spreadsheet-editor