skills/syncfusion/spreadsheet-editor-sdk-skills/syncfusion-vue-spreadsheet-editor/Gen Agent Trust Hub
syncfusion-vue-spreadsheet-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external files (Excel, CSV) and remote API endpoints, which creates a potential surface for malicious instructions to influence the agent.
- Ingestion points: Untrusted data enters the agent context through the file opening functionality (
import-export.md) and data binding from remote APIs via the DataManager (data-binding.md). - Boundary markers: The
SKILL.mdfile defines a strict workflow requiring the agent to ask the user for a delivery mode and perform path validation before any project file modifications occur. - Capability inventory: The skill allows for code generation, writing to a dedicated output folder, and modifying existing project files if explicitly permitted by the user.
- Sanitization: The
SKILL.mdfile contains a dedicated security section instructing the agent to validate, normalize, and sanitize input from remote sources and to reject active content such as macros. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of vendor-specific libraries and interacts with vendor-owned remote services for file processing.
- Evidence: The
getting-started.mdfile instructs users to install the@syncfusion/ej2-vue-spreadsheetpackage. Additionally,import-export.mdreferences official demonstration endpoints ondocument.syncfusion.com. These are recognized as legitimate vendor resources from the author, Syncfusion Inc.
Audit Metadata