syncfusion-vue-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external files (Excel, CSV) and remote API endpoints, which creates a potential surface for malicious instructions to influence the agent.
  • Ingestion points: Untrusted data enters the agent context through the file opening functionality (import-export.md) and data binding from remote APIs via the DataManager (data-binding.md).
  • Boundary markers: The SKILL.md file defines a strict workflow requiring the agent to ask the user for a delivery mode and perform path validation before any project file modifications occur.
  • Capability inventory: The skill allows for code generation, writing to a dedicated output folder, and modifying existing project files if explicitly permitted by the user.
  • Sanitization: The SKILL.md file contains a dedicated security section instructing the agent to validate, normalize, and sanitize input from remote sources and to reject active content such as macros.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of vendor-specific libraries and interacts with vendor-owned remote services for file processing.
  • Evidence: The getting-started.md file instructs users to install the @syncfusion/ej2-vue-spreadsheet package. Additionally, import-export.md references official demonstration endpoints on document.syncfusion.com. These are recognized as legitimate vendor resources from the author, Syncfusion Inc.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:02 AM
Security Audit — agent-trust-hub — syncfusion-vue-spreadsheet-editor