skills/syncfusion/spreadsheet-editor-sdk-skills/syncfusion-wpf-spreadsheet-editor/Gen Agent Trust Hub
syncfusion-wpf-spreadsheet-editor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates code snippets that utilize
System.Diagnostics.Process.Startto launch local files (e.g., Sample.pdf, Sample.png) created during export processes. This is a standard developer practice for demonstrating output but involves executing commands on the host machine. - [DATA_EXPOSURE]: The skill includes code for accessing the local file system to open workbooks (e.g.,
spreadsheet.Open(@"C:\Data\Sample.xlsx")) and insert images from local paths. These operations are scoped to the intended functionality of a spreadsheet editor. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Excel files and DataTables. While the agent is instructed to use only hardcoded reference snippets, the ingestion of external data without explicit boundary markers or sanitization represents a potential attack surface for indirect prompt injection.
- Ingestion points:
SfSpreadsheet.OpenandImportDataTableinreferences/getting-started.md. - Boundary markers: None identified in the reference snippets.
- Capability inventory: File writing via
SfSpreadsheet.SaveAsand process initiation viaProcess.Start. - Sanitization: No explicit sanitization or validation of cell content is present in the provided snippets.
Audit Metadata